5V0-42.21 · Question #31
A customer is using Office 365. How would the VMware SD-WAN recognize this application correctly?
The correct answer is D. VMware SD-WAN will use SSL inspection to detect Office 365. SSL inspection is the identified mechanism VMware SD-WAN uses to recognize Office 365 because Office 365 traffic is TLS-encrypted, meaning traditional DPI cannot read payload content directly. By performing SSL inspection, the SD-WAN edge device can decrypt, inspect, and…
Question
A customer is using Office 365. How would the VMware SD-WAN recognize this application correctly?
Options
- AThe VCE supports prioritization and QoS. Each application is assigned one of the three Service
- BTop SaaS Apps (TLS encrypted) are identified using put. IP and port ranges Other TLS traffic can
- COffice 365 has to be added as part of customizing the Application Map by TCP/UDP port and
- DVMware SD-WAN will use SSL inspection to detect Office 365.
How the community answered
(34 responses)- A3% (1)
- B3% (1)
- C6% (2)
- D88% (30)
Explanation
SSL inspection is the identified mechanism VMware SD-WAN uses to recognize Office 365 because Office 365 traffic is TLS-encrypted, meaning traditional DPI cannot read payload content directly. By performing SSL inspection, the SD-WAN edge device can decrypt, inspect, and re-encrypt the traffic inline to positively identify the application - even when it's hidden behind encryption.
Why the distractors are wrong:
- A describes QoS/prioritization classes, which is a post-identification feature - it tells you what to do with traffic, not how to recognize it.
- B describes IP/port-range matching, which is a valid identification method for some SaaS apps, but it's not the primary mechanism highlighted for Office 365 in this context (and the option is incomplete/garbled).
- C suggests manually adding Office 365 to the Application Map by TCP/UDP port, which would be a manual workaround - not how VMware SD-WAN natively recognizes it out of the box.
Memory tip: Think "SSL = See inside the lock." Office 365 locks its traffic with TLS; VMware SD-WAN needs SSL inspection to see inside the lock and confirm which application is running. If a question asks how SD-WAN identifies encrypted SaaS traffic, SSL inspection is the exam answer.
Note: In practice, VMware SD-WAN also uses SNI (Server Name Indication) and Microsoft-published IP ranges for O365 identification - but for exam purposes, SSL inspection is the targeted concept here.
Topics
Community Discussion
No community discussion yet for this question.