300-415 Exam Questions
455 real 300-415 exam questions with expert-verified answers and explanations. Page 9 of 10.
- Question #401Security and Quality of Service
Which value of the IPsec rekey timer must be set by the engineer for an OMP graceful restart value set for 24 hours?
SD-WANIPsec RekeyOMP Graceful RestartSecurity Timers - Question #402WAN Edge Router Deployment
What are the two requirements for plug-and-play provisioning on Cisco IOS XE SD-WAN devices? (Choose two.)
SD-WAN ProvisioningZero Touch ProvisioningWAN Edge DeploymentDevice Authentication - Question #403Architecture
Which attribute identifies the type of a vRoute?
vRoute AttributesOMPRoute OriginSD-WAN Routing - Question #404Security and Quality of Service
Which statement describes the requirement of integrating a secure internet gateway (SIG) with a Cisco SD-WAN Edge device?
SD-WAN EdgeSecure Internet GatewayCisco UmbrellaIntegration Requirements - Question #405WAN Edge Router Deployment
Which condition must be present to support DRE in a Cisco SD-WAN environment?
DREData Redundancy EliminationFlow SymmetryWAN OptimizationCisco SD-WAN - Question #406Architecture
Which Cloud OnRamp solution is used by partners and vendors without Cisco SD-WAN but still need connectivity to their customers without installing SD-WAN routing appliances on thei...
Cloud OnRampColocationSD-WAN Connectivity - Question #407Policies
Which configuration enables route filtering in an SD-WAN controller?
SD-WAN Route FilteringOMPController ConfigurationTLOC Color - Question #408Management and Operations
Which plane is used to collect vSmart Control Connection statistics for monitoring from the vManage dashboard?
SD-WAN PlanesManagement PlanevManageMonitoring - Question #409Policies
Refer to the exhibit. Site 2 prefers the MPLS circuit to reach site 1 and advertises the routes learned into service VPN. Which policy configuration achieves this?
Cisco SD-WAN PoliciesCentralized Control PolicyOMP Route PreferenceTransport Color - Question #410Router Deployment
Drag and Drop Question. Drag and drop the code snippets from the bottom onto the boxes in the configuration to create a summary of the 10.0.0.0/16 network specifically for its neig...
Route SummarizationRouting Protocol ConfigurationIP AddressingNetwork Advertisement - Question #411Security and Quality of Service
Which feature blocks malware, phishing, and unacceptable requests to provide faster internet access to users in SD-WAN security solutions?
SD-WAN SecurityDNS SecurityThreat PreventionURL Filtering - Question #412WAN Edge Router Deployment
Refer to the exhibit. The sites are connected over different ISP carriers. The client requested that the engineer choose private TLOC colors that would form the control connections...
SD-WAN TLOCWAN Edge configurationTunnel interfaceVPN 0 - Question #413Architecture
Which solution provides enterprises with multiple distributed branch offices that are clustered around major cities or spread over several countries with the ability to regionalize...
Cloud OnRampColocationSD-WAN ArchitectureRegional Routing - Question #414Management and Operations
What is the procedure to add software images to the repository in the Cisco Catalyst SD-WAN manager server?
Software image managementvManage repositorySD-WAN upgrade procedureOut-of-band management - Question #415Policies
Refer to the exhibit A network engineer configures direct internet access for users in a branch. Users in subnet 10.10.0.0/24 and 10.20.0.0/24 must have direct internet access. Whi...
SD-WAN PoliciesvManage Groups of InterestDirect Internet AccessData Prefix - Question #416Security and Quality of Service
Which component calculates Quality of Experience in a Cloud OnRamp environment?
Quality of Experience (QoE)WAN EdgeSD-WAN MonitoringCloud OnRamp - Question #417Policies
Refer to the exhibit. vEdge103 is connected to the headquarters using two different circuits: MPLS and Business Internet. Service VPN 100 must use only the MPLS circuit and drop th...
SD-WAN TLOCVPN PolicyPath SelectionFailover - Question #418Policies
Refer to the exhibit. A customer wants to deploy service insertion at HQ in which traffic from VPN 1 must route to HQ from both sites to go through the firewall. No route leaking w...
Service InsertionFirewall IntegrationVPN ConfigurationSD-WAN Policies - Question #419Policies
A company with a headquarters and two branches enabled dynamic on-demand tunnels on all its devices participating in Cisco SD-WAN. The devices are now waiting for the network team...
Cisco SD-WANCentralized Control PolicyDynamic On-Demand TunnelsSpoke-to-Spoke - Question #420Management and Operations
Which two features are provided by Cisco SD-WAN Cloud Hub with Google Cloud? (Choose two.)
Cisco SD-WAN Cloud HubGoogle Cloud IntegrationAutomated ProvisioningSimplified Management - Question #421Security and Quality of Service
Which type of packet is sent to UTD for action when TLS proxy is enabled on a Cisco SD-WAN device?
SD-WAN SecurityTLS ProxyUTDTLS Handshake - Question #422Policies
Refer to the exhibit. An engineer is configuring internet access at branches using centralized data policies and permitting only one proxy server internet access. Which command com...
SD-WAN PoliciesData PolicyTraffic SteeringProxy Server Configuration - Question #423Security and Quality of Service
How does Cisco Umbrella respond to the client if the FQDN in the DNS query is one of the grey-listed domains?
Cisco UmbrellaDNS SecurityIntelligent ProxyWeb Security - Question #424Policies
Refer to the exhibit. A customer wants to deploy service insertion at site 1, in which traffic from VPN 10 must route to this site through a firewall. A policy must be in place to...
SD-WAN PoliciesService InsertionData PolicyvSmart Configuration - Question #425Policies
An enterprise requires Tier2 sites to communicate with Tier1 and Tier2 sites through hub locations only. Additionally, Tier2 is restricted from establishing BFD sessions with Tier1...
SD-WAN Control PolicyHub-and-Spoke TopologyBFD ConfigurationSite Segmentation - Question #426WAN Edge Router Deployment
Which interface does Cisco Catalyst SD-WAN Cloud OnRamp for IaaS use to set up the customer gateway and map the host VPC to a transit VPC in an AWS environment?
Cloud OnRamp for IaaSAWS IntegrationvEdge InterfaceTransit VPC - Question #427Controller Deployment
What are the minimum number of subnets required for configuring a virtual private cloud in a Cisco Catalyst SD-WAN controller cloud deployment?
SD-WAN Controller Cloud DeploymentVPC NetworkingMinimum SubnetsDeployment Requirements - Question #428WAN Edge Router Deployment
Refer to the exhibit. vEdge102 must form a control connection over MPLS using TLOC extension and dynamic routing. Which configuration accomplishes the task?
SD-WANTLOC ExtensionDynamic RoutingWAN Edge Configuration - Question #429WAN Edge Router Deployment
Refer to the exhibit. CSRV1 must redistribute OMP routes into OSPF Area 1 that must be seen as type 7 LSA by RTR1. CSRV1 must also advertise the default route toward RTR1, which is...
OSPF NSSARoute RedistributionDefault Route OriginationType 7 LSA - Question #430Router Deployment
Refer to the exhibit. Which configuration establishes connectivity between the 172.16.102.0/24 and the 192.168.0.0/24 subnet?
VRFRoute leakingBGPRouter configuration - Question #431WAN Edge Router Deployment
Refer to the exhibit. An engineer is performing a proof of concept before migrating to the Cisco Catalyst SD-WAN solution in the data center by configuring the WAN vEdge101 device....
WAN Edge configurationTunnel interfaceSD-WAN transport colorsVPN 0 - Question #432Architecture
Refer to the exhibit. vEdge101 has six possible routes to connect to spokes. However, only four routes are currently in use. Which CLI configuration ensures that all six routes are...
OMPRoute advertisementPath selectionvSmart configuration - Question #433WAN Edge Router Deployment
Refer to the exhibit. A customer must configure the CSRv Cisco IOS XE SD-WAN router for service insertion on at one of their sites. One of the network consultants trains an enginee...
Cisco SD-WANService InsertionConfiguration TemplatesWAN Edge Router - Question #434WAN Edge Router Deployment
How should an engineer optimize multicast packet distribution throughout the overlay network in SD-WAN?
SD-WAN MulticastMulticast OptimizationWAN Edge RouterPacket Replication - Question #435Policies
The engineer is configuring the vSmart controller to transmit the initial set of non-best routes to the vEdge routers. Which configuration command is required under the Overlay Man...
OMP configurationvSmartRoute advertisementBackup paths - Question #436WAN Edge Router Deployment
Refer to the exhibit. Which command is needed to prevent end users from sending data traffic through CSR101?
OMP ConfigurationRoute AdvertisementData Plane ControlSD-WAN Edge Router - Question #437Policies
Refer to the exhibit. The network team is implementing a TLOC policy in a network with a hub and spoke layout. The spoke sites must prefer their public-internet circuit for routes...
SD-WAN Control PolicyTLOC PolicyvSmart Policy ApplicationHub-Spoke Topology - Question #438Policies
Based on the provided SDWAN topology and route configuration, to steer VPN 1 traffic from sites 101 and 103 through the firewall at site 102, how must the centralized route policy...
Centralized Route PolicyTraffic SteeringvSmart PoliciesPolicy Application - Question #439Security and Quality of Service
Drag and drop the code snippets from the bottom onto the boxes in the configuration to prevent ICMP packets from the internet circuit from reaching users in VPN10 at site 101. Not...
ACLsTraffic FilteringICMP SecurityEdge Security - Question #440Policies
An engineer is creating a policy for VPN1 users. Their scavenger traffic at site 101 must pass through a firewall. Which two match conditions must be selected to enable this policy...
Policy MatchingTraffic ClassificationSD-WAN SecurityVPN Policies - Question #441Policies
Refer to the exhibit. An engineer is modifying an existing data policy for DIA in VPN 23. Web browsing traffic toward government websites must be admitted for DIA. All other traffi...
SD-WAN Data PolicyDirect Internet Access (DIA)Policy Match ConditionsData Prefix List - Question #442Policies
Refer to the exhibit. An enterprise requires spoke sites 102 and 103 to use the MPLS circuit to reach the 172.16.101.0/24 subnet (Service VPN 100) advertised by site 101 (Hub Site)...
SD-WAN PoliciesControl PolicyTLOC PreferenceOMP Route Manipulation - Question #443Security and Quality of Service
Refer to the exhibit. An engineer is enabling command line access via MPLS for in-band management. Which command completes the partial SD-WAN interface configuration with the highe...
SD-WAN Interface ConfigurationIn-band ManagementSecurity Best PracticesSSH - Question #444Security and Quality of Service
Which three commands correctly configure an access list entry to permit control connections from SD-WAN controllers while blocking non-control connections?
SD-WAN Control PlaneAccess ListsPort NumbersNetwork Security - Question #445Security and Quality of Service
Which phrase describes the method Cisco Umbrella employs to provide DNS security?
Cisco UmbrellaDNS securityDNS resolutionThreat detection - Question #446Security and Quality of Service
Which Certificate of Authority (CA) option is used when configuring a TLS proxy in the Cisco Catalyst SD-WAN environment?
TLS ProxyCertificate AuthoritySD-WAN ManagerSD-WAN Security - Question #447Security and Quality of Service
Which benefit does packet duplication provide?
Packet DuplicationSD-WAN ReliabilityPacket Loss PreventionQoS - Question #448Security and Quality of Service
A company using Catalyst SD-WAN Manager as its root certificate authority server must generate a root certificate using the vShell (Linux) built into the CLI of Catalyst SD-WAN Man...
SD-WAN SecurityPKI ManagementOpenSSL CommandsCertificate Authority - Question #449Management and Operations
What is the primary purpose of monitoring "Event Trace" for OMP agent and SD-WAN subsystems?
MonitoringSD-WAN TracingOMPDiagnostics - Question #450WAN Edge Router Deployment
Refer to the exhibit. A WAN Edge device cannot connect to SD-WAN Validator; however, can ping it. Which action resolves the issue?
SD-WAN TroubleshootingWAN Edge EnrollmentCertificatesControl Plane