nerdexam
Cisco

300-420 · Question #284

Which two statements describes Cisco SD-Access? (Choose two.)

The correct answer is A. software-defined segmentation and policy enforcement based on user identity and group D. programmable overlays enabling network virtualization across the campus. Cisco SD-Access implements software-defined segmentation and policy enforcement based on user identity and group, and it utilizes programmable overlays to enable network virtualization across the campus infrastructure.

Advanced Enterprise Campus Networks

Question

Which two statements describes Cisco SD-Access? (Choose two.)

Options

  • Asoftware-defined segmentation and policy enforcement based on user identity and group
  • Ban overlay for the wired infrastructure in which traffic is tunneled via a GRE tunnel to a mobility
  • Can automated encryption/decryption engine for highly secured transport requirements
  • Dprogrammable overlays enabling network virtualization across the campus
  • Ea collection of tools and applications that are a combination of loose and tight coupling

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    3% (1)
  • C
    7% (2)

Why each option

Cisco SD-Access implements software-defined segmentation and policy enforcement based on user identity and group, and it utilizes programmable overlays to enable network virtualization across the campus infrastructure.

Asoftware-defined segmentation and policy enforcement based on user identity and groupCorrect

SD-Access provides end-to-end software-defined segmentation using Virtual Networks (VNs) and fine-grained micro-segmentation with Scalable Group Tags (SGTs), enforcing policies based on user identity and group membership.

Ban overlay for the wired infrastructure in which traffic is tunneled via a GRE tunnel to a mobility

SD-Access uses VXLAN, not GRE tunnels, for its overlay encapsulation, and while it supports mobility, the statement's description of GRE tunneling to a mobility agent is not accurate for its core overlay mechanism.

Can automated encryption/decryption engine for highly secured transport requirements

While SD-Access incorporates security features, it is not primarily defined as an 'automated encryption/decryption engine' for transport; its main focus is on segmentation and policy enforcement.

Dprogrammable overlays enabling network virtualization across the campusCorrect

SD-Access builds a programmable overlay network, primarily using VXLAN encapsulation, which virtualizes the entire campus network infrastructure to simplify management and enable flexible policy application.

Ea collection of tools and applications that are a combination of loose and tight coupling

This description is too vague and general; SD-Access is a tightly integrated architectural solution rather than a collection of loosely or tightly coupled tools and applications.

Concept tested: Cisco SD-Access core characteristics

Source: https://www.cisco.com/c/en/us/solutions/enterprise-networks/software-defined-access/what-is-software-defined-access-sda.html

Topics

#Cisco SD-Access#Network Virtualization#Segmentation#Overlay Networking

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice