300-440 Exam Questions
73 real 300-440 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
An engineer is implementing a highly secure multitier application in AWS that includes S3. RDS, and some additional private links. What is critical to keep the traffic safe?
- Question #2
What is the role of service providers to establish private connectivity between on-premises networks and Google Cloud resources?
- Question #3
Refer to the exhibits. An engineer must redistribute IBGP routes into OSPF to connect an on- premises network to a cloud provider. Which command must be configured on router R2?
- Question #4
An engineer must configure an IPsec tunnel to the cloud VPN gateway. Which Two actions send traffic into the tunnel? (Choose two.)
- Question #5
Which architecture model establishes internet-based connectivity between on-premises networks and AWS cloud resources?
- Question #6
A cloud engineer is setting up a new set of nodes in the AWS EKS cluster to manage database integration with Mongo Atlas. The engineer set up security to Mongo but now wants to ens...
- Question #7
Which feature is unique to Cisco SD-WAN IPsec tunnels compared to native IPsec VPN tunnels?
- Question #8
Which approach does a centralized internet gateway use to provide connectivity to SaaS applications?
- Question #9
Refer to the exhibit. An engineer needs to configure a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router and Amazon Web Services (AWS). Which configurati...
- Question #10
Refer to the exhibit. An engineer successfully brings up the site-to-site VPN tunnel between the remote office and the AWS virtual private gateway, and the site-to-site routing wor...
- Question #11
Refer to the exhibit. A company uses Cisco SD-WAN in the data center. All devices have the default configuration. An engineer attempts to add a new centralized control policy in Ci...
- Question #12
A company with multiple branch offices wants a suitable connectivity model to meet these network architecture requirements: - high availability - quality of service (QoS) - multiho...
- Question #13
A company has multiple branch offices across different geographic locations and a centralized data center. The company plans to migrate Its critical business applications to the pu...
- Question #14
Which method is used to create authorization boundary diagrams (ABDs)?
- Question #15
Refer to the exhibit. While troubleshooting an IPsec connection between a Cisco WAN edge router and an Amazon Web Services (AWS) endpoint, a network engineer observes that the secu...
- Question #16
Refer to the exhibit. A network engineer discovers that the policy that is configured on an on- premises Cisco WAN edge router affects only the route tables of the specific devices...
- Question #17
A company with multiple branch offices wants a connectivity model to meet its network architecture requirements. The company focuses on ensuring low latency and efficient routing f...
- Question #18
Which Microsoft Azure service enables a dedicated and secure connection between an on- premises infrastructure and Azure data centers through a colocation provider?
- Question #19
An engineer must enable the OMP advertisement of BGP routes for a specific VRF instance on a Cisco IOS XE SD-WAN device. What should be configured after the global address-family i...
- Question #20
Refer to the exhibits. An engineer troubleshoots a Cisco SD-WAN connectivity issue between an on-premises data center WAN Edge and a public cloud provider WAN Edge. The engineer di...
- Question #21
Refer to the exhibits. While troubleshooting, a network engineer discovers that the backup path fails between ASBR3 and ASBR4 for traffic between BGP AS6000 and BGP AS6500 when the...
- Question #22
Refer to the exhibits. An engineer needs to configure a site-to-site IPsec VPN connection between an on premises Cisco IOS XE router and Amazon Web Services (AWS). Which two IP pre...
- Question #24
Refer to the exhibits. An engineer must redistribute OSPF internal routes into BGP to connect an on-premises network to a cloud provider without introducing extra routes. Which two...
- Question #25
Refer to the exhibits. An engineer must redistribute only the 10.0.10.0/24 network into BGP to connect an on-premises network to a public cloud provider. These routes are currently...
- Question #26
Refer to the exhibits. An engineer must redistribute OSPF internal routes into BGP to connect an on-premises network to a cloud provider. Which two commands should the engineer run...
- Question #39
Which feature of Google Cloud VPN establishes secure internet-based connectivity between on- premises networks and Google Cloud resources?
- Question #40
Which model provides the middle mile from colocation and on-demand private connectivity to the cloud, where branches connect via the internet as a first mile?
- Question #41
What is an advantage of using a dedicated connection to a SaaS provider instead of public internet connectivity?
- Question #42
A company has a distributed network that consists of multiple branch offices, a corporate data center, and public cloud infrastructure that is hosted in AWS. The company requires h...
- Question #43
Which service allows for a dedicated, low latency connection between an organization's on- premises infrastructure and Google Cloud Platform through a colocation provider?
- Question #44
Refer to the exhibit. An engineer must redistribute 10.10.10.0/24 routes into BGP to connect the on-premises network to a cloud provider. Which command must be configured on the ro...
- Question #45
An engineer is implementing a highly secure multitier application in AWS that includes S3. RDS, and several additional private links. Which two features are required to keep the tr...
- Question #46
Which Microsoft Azure-native security feature controls inbound connectivity to an Azure virtual machine?
- Question #47
Which threat models are required for penetration testing of a FedRAMP network?
- Question #48
Which two types of target gateways, under VPC > VPN connections, should an engineer select to configure an AWS site-to-site VPN? (Choose two.)
- Question #49
Refer to the exhibit. An engineer must configure a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router and AWS. Which command completes the configuration?
- Question #51
Refer to the exhibit. An engineer establishes IPsec, internet-based, secure cloud connectivity between an on-premises Cisco IOS XE router and a native AWS endpoint. Which parameter...
- Question #52
Refer to the exhibit. An engineer is establishing a VPN tunnel from the Google Cloud VPN gateway toward the external IP addresses of the Montreal branch and the Toronto site. The e...
- Question #53
Refer to the exhibit. Which tunnel mode must be configured to allow cloud gateway connectivity to the VPC through the transit gateway using an AWS IPSec VPN approach?
- Question #54
Which two types of target gateways are used to configure an AWS site-to-site VPN? (Choose two.)
- Question #55
Refer to the exhibit. An engineer is troubleshooting an IPSec connectivity issue between an on- premises data center and a public cloud provider. Which two conclusions should the e...
- Question #56
Refer to the exhibit. An engineer must configure a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router and Amazon Web Services. Which IP address completes...
- Question #57
A network engineer configures a localized data policy on a router, but the configuration blocks data traffic between the routers on the SD-WAN overlay network. The configuration al...
- Question #58
Refer to the exhibit. An engineer must configure Cisco Catalyst SD-WAN connectivity between an on-premises data center and AWS. The GigabitEthernet0 interface is used for public In...
- Question #59
An engineer must deploy Cisco Catalyst SD-WAN, route software as a service application traffic for optimal performance, and route other types of traffic through the data center. Wh...
- Question #60
Refer to the exhibit. The policy has failed to stop DOS attacks from within the service VPN 100. The counter shows no logб but the destination network reported DOS attacks from net...
- Question #61
An engineer configured a Cisco Catalyst SD-WAN router for SIG and entered the secure- internet-gateway configuration level What is the next step to implement a Cisco SIG using Zsca...
- Question #62
Refer to the exhibit. The output shows a configured jitter variance of 10 ms. Which path is optimal for network traffic?
- Question #63
What is the advantage of using Cisco Catalyst SD-WAN for connectivity between on-premises networks and cloud resources?
- Question #64
An engineer needs to configure Cisco Catalyst SD-WAN connectivity between an on-premises data center and AWS. The GigabitEthernet1 interface is used for public Internet connectivit...