nerdexam
Cisco

300-420 · Question #270

Which two statements regarding Cisco SD-WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two.)

The correct answer is A. Only authorized controllers are allowed to communicate back to the vEdge router after the vEdge D. In case of direct Internet access, the only traffic allowed back is the traffic matching the state table. Cisco SD-WAN vEdge routers mitigate DoS attacks by restricting controller communication to only authorized vSmart controllers and by employing stateful firewall inspection for direct internet access traffic. These measures ensure only legitimate control plane and return data…

WAN for Enterprise Networks

Question

Which two statements regarding Cisco SD-WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two.)

Options

  • AOnly authorized controllers are allowed to communicate back to the vEdge router after the vEdge
  • BBy default, integrated IDS'IPS on inside and (WAN) side interfaces.
  • CThe vEdge routers run on hardened Linux operating systems.
  • DIn case of direct Internet access, the only traffic allowed back is the traffic matching the state table
  • EOpen Certificate Authority and automated enrollment feature.

How the community answered

(38 responses)
  • A
    84% (32)
  • B
    5% (2)
  • C
    3% (1)
  • E
    8% (3)

Why each option

Cisco SD-WAN vEdge routers mitigate DoS attacks by restricting controller communication to only authorized vSmart controllers and by employing stateful firewall inspection for direct internet access traffic. These measures ensure only legitimate control plane and return data plane traffic reaches the router.

AOnly authorized controllers are allowed to communicate back to the vEdge router after the vEdgeCorrect

vEdge routers establish secure, authenticated connections with vSmart controllers, ensuring that only trusted and authorized controllers can establish control plane communication back to the router. This prevents rogue controllers from orchestrating DoS attacks.

BBy default, integrated IDS'IPS on inside and (WAN) side interfaces.

While Cisco SD-WAN solutions can integrate with security services, vEdge routers do not have integrated IDS/IPS by default on all interfaces; security features are often deployed via security policies or integrated with cloud security services.

CThe vEdge routers run on hardened Linux operating systems.

Running on a hardened Linux OS contributes to general security, but it is a foundational security practice rather than a specific feature directly mitigating DoS attacks in the same manner as authorized controller communication or stateful firewalling.

DIn case of direct Internet access, the only traffic allowed back is the traffic matching the state tableCorrect

When a vEdge router has direct internet access, its integrated stateful firewall ensures that only return traffic that matches an established outbound connection in its state table is permitted to enter the network. This prevents unsolicited inbound connections that could be part of a DoS attack.

EOpen Certificate Authority and automated enrollment feature.

An Open Certificate Authority (CA) and automated enrollment provide secure device identity and trust for authentication, which is crucial for overall security, but it is not a direct DoS mitigation mechanism itself.

Concept tested: Cisco SD-WAN vEdge DoS attack mitigation

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-security-overview.html

Topics

#SD-WAN Security#DoS Mitigation#Stateful Firewall#Control Plane Security

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice