300-415 Exam Questions
455 real 300-415 exam questions with expert-verified answers and explanations. Page 6 of 10.
- Question #251Policies
A customer has 1 to 100 service VPNs and wants to restrict outbound updates for VPN1. Which control policy configuration restricts these updates?
SD-WAN Control PolicyVPN FilteringvSmart PolicyRoute Filtering - Question #252Policies
What is the default value for the number of paths advertised per prefix in the OMP feature template?
OMPFeature TemplateSD-WAN RoutingDefault Values - Question #253Policies
Which two vRoute attributes should be matched or set in vSmart policies and modified by data policies? (Choose two.)
SD-WAN PoliciesvSmart PoliciesData PoliciesvRoute Attributes - Question #254Security and Quality of Service
What are the two components of an application-aware firewall? (Choose two.)
Application FirewallFirewall ComponentsZone-Based FirewallNetwork Security - Question #255Security and Quality of Service
What are the two prerequisites for a Cloud OnRamp for SaaS feature to show the accurate vQoE score? (Choose two.)
Cloud OnRamp for SaaSvQoESD-WAN ConfigurationNAT - Question #256Management and Operations
Which website allows access to visualize the geography screen from vManager using the internet?
vManageGeographical VisualizationOpenStreetMap Integration - Question #257Security and Quality of Service
Which queue must an engineer configure for control and BFD traffic for convergence on a WAN Edge router?
QoSControl Plane TrafficBFDTraffic Prioritization - Question #258Policies
Refer to the exhibit. A company requires a data traffic policy that uses the "mpls" and "biz-internet" colors for Google Apps if the SLA is met. A link with the "public-internet" c...
SD-WANApp-Route PolicySLATraffic Engineering - Question #259Management and Operations
How are custom application ports monitored in Cisco SD-WAN controllers?
SD-WAN monitoringApplication awarenessvManage configurationvAnalytics - Question #260Controller Deployment
Which storage format is used when vManage is deployed as a virtual machine on a KVM hypervisor?
vManage deploymentKVM hypervisorVirtual disk format - Question #261Policies
An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router's local site and then change the DSCP value to DSCP 18 before sending it over t...
DSCP RemarkingLocalized PolicyQoSAccess Control List - Question #262Management and Operations
Which two resource data types are used to collect information for monitoring using REST API in Cisco SD-WAN? (Choose two.)
SD-WAN REST APIMonitoringAPI Data Types - Question #263Policies
Refer to the exhibit. An engineer must block FTP traffic coming in from a particular Service VPN on a WAN Edge device. Which set of steps achieves this goal?
Localized PolicyAccess Control ListWAN Edge SecurityvManage Templates - Question #264Security and Quality of Service
Which feature delivers traffic to the Cisco Umbrella SIG cloud from a Cisco SD-WAN domain?
SD-WAN Cloud SecurityUmbrella SIG IntegrationIPsec TunnelsTraffic Steering - Question #265Architecture
What must an engineer consider when deploying an SD-WAN on-premises architecture based on ESXi hypervisor?
SD-WAN on-premisesESXi deploymentController responsibilitiesBackup and disaster recovery - Question #266Security and Quality of Service
Which protocol detects path status (up/down), measures loss/latency/jitter, and measures the quality of the IPsec tunnel MTU?
BFDSD-WANTunnel monitoringPath performance - Question #267Controller Deployment
Refer to the exhibit. vManage and vBond have an issue establishing a connection to vSmart. Which two actions does the administrator take to fix the issue? (Choose two.)
SD-WAN Control PlaneController CertificatesController ConnectivityTroubleshooting - Question #268Controller Deployment
Refer to the exhibit. An engineer is troubleshooting a control connection issue on a WAN Edge that device shows socket errors. The packet capture shows some ICMP packets dropped be...
SD-WAN Control PlanevManage High AvailabilityTroubleshootingWAN Edge Connectivity - Question #269WAN Edge Router Deployment
Which color type is assigned when a TLOC is configured behind NAT?
TLOCNATSD-WAN ColorsWAN Edge Configuration - Question #270Architecture
Which attribute is used to tie all the controllers together by vManage?
Cisco SD-WANController IdentityFabric FormationOrganization Name - Question #271Security and Quality of Service
An engineer is applying QoS scheduling for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router. Which command accomplishes the task?
Cisco SD-WAN QoSWAN Edge QoSQoS SchedulingTransport-side QoS - Question #272Policies
The Cisco SD-WAN engineer is configuring service chaining for a next-generation firewall located at the headquarters. Which configuration creates the service?
Service ChainingvManage ConfigurationConfiguration TemplatesNGFW - Question #273Architecture
Which component of the Cisco SD-WAN network assures that only valid customer nodes are participating in the overlay network?
vSmart ControllerSD-WAN ArchitectureControl PlaneNode Validation - Question #274Controller Deployment
How many vManage NMSs should be installed in each domain to achieve scalability and redundancy?
vManage deploymentScalabilityRedundancyClustering - Question #275Management and Operations
Which REST API call checks the status of an action that is performed on a device?
REST APIDevice MonitoringAPI CallsOperational Status - Question #276Policies
Which two actions must be taken to allow certain department to require firewall protection when interacting with data center networks without including other departments? (Choose t...
SD-WAN Service ChainingService AdvertisementvSmart ControllerTraffic Steering - Question #277WAN Edge Router Deployment
Which behavior describes a WAN Edge router running dual DIA when its DPI engine has identified a cloud SaaS application?
WAN Edge RouterDPISaaS OptimizationApplication-aware routing - Question #278Policies
Which Cisco SD-WAN component centralizes policy configuration?
Cisco SD-WAN componentsvSmart controllerPolicy configurationControl plane - Question #279Architecture
Which multicast component is irrelevant when defining a multicast replicator outside the local network without any multicast sources or receivers?
MulticastSD-WAN OverlayOMPPIM - Question #280Policies
An organization wants to discover, monitor, and track the applications running on the WAN Edge device on the LAN. Which configuration achieves the goal?
Application VisibilityLocalized PolicyCisco SD-WANWAN Edge - Question #281Security and Quality of Service
What are the components of zone configuration in an application-aware firewall?
Zone-Based FirewallSecurity ZonesZone PairFirewall Components - Question #282WAN Edge Router Deployment
Which configuration on the WAN Edge meets the requirement?
WAN Edge configurationVPN 0 transportTunnel interfaceEIGRP routing - Question #283Policies
QUESTION 329 Which data policy configuration influences BGP routing traffic flow from LAN to WAN?
BGP Traffic EngineeringAS-Path PrependSD-WAN Control PolicyOutbound Policy - Question #284Architecture
Which cloud-based component in Cisco SD-WAN is responsible for establishing a secure connection to each WAN Edge router and distributes routes and policy information via OMP?
Cisco SD-WAN componentsvSmart controllerOMPControl plane - Question #285WAN Edge Router Deployment
What is the main purpose of using TLOC extensions in WAN Edge router configuration?
SD-WANTLOC ExtensionsWAN Edge RedundancyTransport Redundancy - Question #286Policies
Which control policy assigned to branches in the out direction establishes a strict hub-and-spoke topology for VPN2?
Centralized Control PolicyHub-and-Spoke TopologyVPN RoutingPolicy Direction - Question #287Policies
Refer to the exhibit. Company ABC has a hub-and-spoke topology in place and currently is load balancing their data traffic at the hub site over MPLS and the public Internet. The le...
SD-WAN PoliciesPath PreferenceApplication-Aware RoutingHub-and-Spoke Topology - Question #288Policies
Refer to the exhibit. Which configuration must the engineer use to form underlay connectivity for the Cisco SD-WAN network?
SD-WAN Control PolicyOMPTLOCUnderlay Connectivity - Question #289Security and Quality of Service
Refer to the exhibit. An engineer must configure a QoS policy between the hub and site A (spoke) over a standard Internet circuit where traffic shaping is adjusted based on availab...
SD-WAN QoSAdaptive QoSWAN Edge ConfigurationTunnel Interface - Question #290WAN Edge Router Deployment
An engineer must configure VRRP for redundancy on WAN Edge router 1 running an earlier version than 20.6, considering WAN Edge router2 is configured correctly. Which configuration...
VRRPWAN Edge ConfigurationSD-WAN VPNsInterface Configuration - Question #291Security and Quality of Service
Which set of key security components of authentication, encryption, and integrity is used to establish an IPsec tunnel in the Cisco SD-WAN solution?
IPsecSD-WAN SecurityEncryptionAuthentication - Question #292Controller Deployment
How many vBond controllers must be installed when vManager is installed in a multitenancy environment for four tenants?
vBondMultitenancyController DeploymentCisco SD-WAN - Question #293Controller Deployment
What is the advantage of installing the controller on-premises?
Controller deploymentOn-premises deploymentControl planeData plane control - Question #294Management and Operations
How many concurrent sessions does a vManager REST API have before it invalidates the least recently used session if the maximum concurrent session number is reached?
vManager APIREST API sessionsConcurrent session limitsAPI management - Question #295Policies
An engineer creates this data policy for DIA for VPN 10: data-policy DIA vpn-list VPN-10 sequence 10 match destination-data-prefix-list INTERNAL-NETWORKS ! action accept Which poli...
SD-WAN Data PolicyDirect Internet Access (DIA)NATPolicy Sequencing - Question #296WAN Edge Router Deployment
An engineer must avoid routing loops on the SD-WAN fabric for routes advertised between data center sites. Which BGP loop prevention attribute must be configured on the routers to...
BGPLoop PreventionAS-PathSD-WAN Routing - Question #297Architecture
Which routing protocol has the highest default administrative distance?
OMPAdministrative distanceRouting protocolsSD-WAN routing - Question #298Controller Deployment
How should the IP addresses be assigned for all members of a Cisco vManager cluster located in the same data center?
vManage clusterIP addressingNetwork designController deployment - Question #299Security and Quality of Service
Which encryption algorithm is used for encrypting SD-WAN data plane traffic?
SD-WAN SecurityData Plane EncryptionAES-256 GCMIPsec - Question #300WAN Edge Router Deployment
A WAN Edge device has several service VPNs with no routing protocol configured in the service VPN. The device must be configured so that all connected routes visible in OMP for VPN...
OMPRoute AdvertisementWAN Edge ConfigurationService VPNs