nerdexam
Cisco

300-415 · Question #7

When VPNs are grouped to create destination zone, how many zones can a VPN be part of?

The correct answer is C. one. In Cisco SD-WAN, when VPNs are used to create destination zones for security policies, a single VPN can only be part of one destination zone at a time.

Security and Quality of Service

Question

When VPNs are grouped to create destination zone, how many zones can a VPN be part of?

Options

  • Atwo
  • Bfour
  • Cone
  • Dthree

How the community answered

(67 responses)
  • A
    1% (1)
  • B
    6% (4)
  • C
    90% (60)
  • D
    3% (2)

Why each option

In Cisco SD-WAN, when VPNs are used to create destination zones for security policies, a single VPN can only be part of one destination zone at a time.

Atwo

Allowing a VPN to be part of two zones would create policy ambiguity and potentially security loopholes.

Bfour

Allowing a VPN to be part of four zones would introduce significant complexity and policy conflicts.

ConeCorrect

When defining security zones in Cisco SD-WAN, a VPN can only be a member of one zone. This is a fundamental design principle to ensure unambiguous policy application and prevent conflicting security rules when traffic traverses zones.

Dthree

Allowing a VPN to be part of three zones would introduce significant complexity and policy conflicts.

Concept tested: SD-WAN security zone VPN membership

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/sdwan-security-cg-book/security-overview.html

Topics

#VPNs#Security Zones#SD-WAN Security#Zone-based Firewall

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice