nerdexam
Cisco

400-007 · Question #372

400-007 Question #372: Real Exam Question with Answer & Explanation

The correct answer is A. Build virtual networks that pass over the network. When two sites are only reachable via the public Internet and the corporate network is unintentionally segmented, building a virtual overlay network (VPN) over the Internet restores logical private connectivity between them.

Designing Network Infrastructure

Question

Network designers often segment networks by creating modules for various reasons. Sometimes however a network can be unintentionally segmented. For instance, if the only way to connect a remote site to a headquarters or regional site is to connect them both to the public Internet the corporate network is now unintentionally segmented. Which of the following option can be used to desegment the network in this situation?

Options

  • ABuild virtual networks that pass over the network
  • BMark traffic for special handling through quality of service
  • CConfigure little to no control data plane policy
  • DBlock specific sources from reaching specific destinations

Explanation

When two sites are only reachable via the public Internet and the corporate network is unintentionally segmented, building a virtual overlay network (VPN) over the Internet restores logical private connectivity between them.

Common mistakes.

  • B. Quality of Service marks and prioritizes existing traffic flows but does not create connectivity between networks that cannot already reach each other.
  • C. Removing control and data plane policy eliminates security and traffic management without establishing any path between the segmented network segments.
  • D. Blocking specific sources from reaching specific destinations further restricts reachability rather than restoring connectivity between the segmented sites.

Concept tested. VPN overlay networks for corporate network desegmentation

Reference. https://www.cisco.com/c/en/us/tech/wan/virtual-private-networks-vpn/index.html

Topics

#network segmentation#VPN tunneling#WAN design#overlay networks

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice