nerdexam
Cisco

400-007 · Question #357

A large enterprise plans to enable direct internet access for specific SaaS applications from its remote branch sites by using local broadband internet circuits. Only traffic to specific cloud SaaS…

The correct answer is A. Define a policy-based redirect to the applications. This question tests knowledge of how Cisco SD-WAN enables selective direct internet access (DIA) for specific SaaS applications at branch sites using traffic steering policies.

Designing Network Services

Question

A large enterprise plans to enable direct internet access for specific SaaS applications from its remote branch sites by using local broadband internet circuits. Only traffic to specific cloud SaaS applications will be allowed direct internet access and all other internet-bound traffic will follow its usual path. The customer wants to leverage its existing SD-WAN solution and cloud provider integration. Which action must be taken on the remote branch routers to meet the requirements?

Options

  • ADefine a policy-based redirect to the applications.
  • BEnable Cloud OnRamp for the branch sites.
  • CConfigure IPsec to the cloud provider.
  • DImplement direct connect for site connectivity.

How the community answered

(24 responses)
  • A
    71% (17)
  • B
    8% (2)
  • C
    4% (1)
  • D
    17% (4)

Why each option

This question tests knowledge of how Cisco SD-WAN enables selective direct internet access (DIA) for specific SaaS applications at branch sites using traffic steering policies.

ADefine a policy-based redirect to the applications.Correct

In Cisco SD-WAN, a policy-based redirect (data policy configured in vManage) allows the administrator to match specific application traffic and redirect it to the local internet breakout interface, enabling direct internet access only for designated SaaS applications. All other traffic continues to follow the default SD-WAN overlay path, satisfying the requirement to selectively allow only certain applications to use the local broadband circuit.

BEnable Cloud OnRamp for the branch sites.

Cloud OnRamp for SaaS optimizes the SD-WAN path to SaaS providers across the overlay fabric but does not by itself configure selective local internet breakout policies for specific applications at branch sites.

CConfigure IPsec to the cloud provider.

Configuring IPsec to the cloud provider establishes a private tunnel to cloud infrastructure and does not address selective direct internet access for SaaS applications using existing local broadband.

DImplement direct connect for site connectivity.

Direct connect is a dedicated private circuit solution to cloud providers such as AWS Direct Connect or Azure ExpressRoute, which is incompatible with using local broadband internet circuits for DIA.

Concept tested: SD-WAN policy-based redirect for selective DIA

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/policies/ios-xe-17/policies-book-xe/m-traffic-policies.html

Topics

#SD-WAN#Cloud OnRamp#policy-based redirect#SaaS

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice