nerdexam
Broadcom-VMware

5V0-42.21 · Question #31

A customer is using Office 365. How would the VMware SD-WAN recognize this application correctly?

The correct answer is D. VMware SD-WAN will use SSL inspection to detect Office 365. SSL inspection is the identified mechanism VMware SD-WAN uses to recognize Office 365 because Office 365 traffic is TLS-encrypted, meaning traditional DPI cannot read payload content directly. By performing SSL inspection, the SD-WAN edge device can decrypt, inspect, and…

SD-WAN Architecture and Technologies

Question

A customer is using Office 365. How would the VMware SD-WAN recognize this application correctly?

Options

  • AThe VCE supports prioritization and QoS. Each application is assigned one of the three Service
  • BTop SaaS Apps (TLS encrypted) are identified using put. IP and port ranges Other TLS traffic can
  • COffice 365 has to be added as part of customizing the Application Map by TCP/UDP port and
  • DVMware SD-WAN will use SSL inspection to detect Office 365.

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    6% (2)
  • D
    88% (30)

Explanation

SSL inspection is the identified mechanism VMware SD-WAN uses to recognize Office 365 because Office 365 traffic is TLS-encrypted, meaning traditional DPI cannot read payload content directly. By performing SSL inspection, the SD-WAN edge device can decrypt, inspect, and re-encrypt the traffic inline to positively identify the application - even when it's hidden behind encryption.

Why the distractors are wrong:

  • A describes QoS/prioritization classes, which is a post-identification feature - it tells you what to do with traffic, not how to recognize it.
  • B describes IP/port-range matching, which is a valid identification method for some SaaS apps, but it's not the primary mechanism highlighted for Office 365 in this context (and the option is incomplete/garbled).
  • C suggests manually adding Office 365 to the Application Map by TCP/UDP port, which would be a manual workaround - not how VMware SD-WAN natively recognizes it out of the box.

Memory tip: Think "SSL = See inside the lock." Office 365 locks its traffic with TLS; VMware SD-WAN needs SSL inspection to see inside the lock and confirm which application is running. If a question asks how SD-WAN identifies encrypted SaaS traffic, SSL inspection is the exam answer.

Note: In practice, VMware SD-WAN also uses SNI (Server Name Indication) and Microsoft-published IP ranges for O365 identification - but for exam purposes, SSL inspection is the targeted concept here.

Topics

#Application Recognition#SSL Inspection#SaaS Detection#Office 365

Community Discussion

No community discussion yet for this question.

Full 5V0-42.21 Practice