300-415 · Question #7
When VPNs are grouped to create destination zone, how many zones can a VPN be part of?
The correct answer is C. one. In Cisco SD-WAN, when VPNs are used to create destination zones for security policies, a single VPN can only be part of one destination zone at a time.
Question
Options
- Atwo
- Bfour
- Cone
- Dthree
How the community answered
(67 responses)- A1% (1)
- B6% (4)
- C90% (60)
- D3% (2)
Why each option
In Cisco SD-WAN, when VPNs are used to create destination zones for security policies, a single VPN can only be part of one destination zone at a time.
Allowing a VPN to be part of two zones would create policy ambiguity and potentially security loopholes.
Allowing a VPN to be part of four zones would introduce significant complexity and policy conflicts.
When defining security zones in Cisco SD-WAN, a VPN can only be a member of one zone. This is a fundamental design principle to ensure unambiguous policy application and prevent conflicting security rules when traffic traverses zones.
Allowing a VPN to be part of three zones would introduce significant complexity and policy conflicts.
Concept tested: SD-WAN security zone VPN membership
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/sdwan-security-cg-book/security-overview.html
Topics
Community Discussion
No community discussion yet for this question.