Summer Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

300-440 Designing and Implementing Cloud Connectivity (ENCC) Questions and Answers

Questions 4

An engineer must configure a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router In Controller mode and AWS. The IKE version must be changed from IKEv1to IKEv2 in Cisco vManage. Drag and drop the steps from the left onto the order on the right to complete the configuration.

300-440 Question 4

Options:

Buy Now
Questions 5

An engineer must edit the settings of a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router and Amazon Web Services (AWS). IPsec must be configured to support multiple peers and failover after 120 seconds of idle time on the first entry of the crypto map named Cisco. Drag and drop the commands from the left onto the order on the right.

300-440 Question 5

Options:

Buy Now
Questions 6

An engineer must configure a CLI add-on feature template in Cisco vManage for enhanced policy-based routing (ePBR) for IPv4. These configurations were deleted:

• licensing config enable false

• licensing config privacy hostname true

• licensing config privacy version false

• licensing config utility utility-enable true

Drag and drop the steps from the left onto the order on the right to complete the configuration.

300-440 Question 6

Options:

Buy Now
Questions 7

Refer to the exhibit.

300-440 Question 7

Drag and drop the steps from the left onto the order on the right to configure a site-to-site VPN connection between an on-premises Cisco IOS XE router and Amazon Web Services (AWS).

300-440 Question 7

Options:

Buy Now
Questions 8

A company with multiple branch offices wants a connectivity model to meet its network architecture requirements. The company focuses on ensuring low latency and efficient routing for its critical business applications. Which connectivity model meets these requirements?

Options:

A.

hub-and-spoke topology with SD-WAN technology, using dynamic routing and OSPF as the routing protocol

B.

fully meshed topology with SD-WAN technology, using dynamic routing and BGP as the routing protocol

C.

point-to-point topology using dedicated leased lines and static routing

D.

star topology with internet-based VPN connections and static routing

Buy Now
Questions 9

Refer to the exhibit.

300-440 Question 9

A company uses Cisco SD-WAN in the data center. All devices have the default configuration. An engineer attempts to add a new centralized control policy in Cisco vManage but receives an error message. What is the problem?

Options:

A.

A centralized control policy is already applied to the specific site ID and direction

B.

The policy for "Hub" should be applied in the outbound direction, and the policy for "All-Site" should be applied inbound.

C.

Apply an additional outbound control policy to override the site ID overlaps.

D.

Site-list "All-Site" should be configured with a new match sequence that is lower than the sequence for site-list "Hub*.

Buy Now
Questions 10

300-440 Question 10

300-440 Question 10

Refer to the exhibits. An engineer must redistribute only the 10.0.10.0/24 network into BGP to connect an on-premises network to a public cloud provider. These routes are currently redistributed:

300-440 Question 10

Which command is missing on router R2?

Options:

A.

neighbor 10.0.10.2 remote-as 100

B.

redistribute ospf 1 match internal

C.

redistribute ospf 1 match external

D.

neighbor 10.0.10.0/24 remote-as 100

Buy Now
Questions 11

300-440 Question 11

Refer to the exhibit. An engineer successfully brings up the site-to-site VPN tunnel between the remote office and the AWS virtual private gateway, and the site-to-site routing works correctly. However, the end-to-end ping between the office user PC and the AWS EC2 instance is not working. Which two actions diagnose the loss of connectivity? (Choose two.)

Options:

A.

Check the network security group rules on the host VNET.

B.

Check the security group rules for the host VPC.

C.

Check the IPsec SA counters.

D.

On the Cisco VPN router, configure the IPsec SA to allow ping packets.

E.

On the AWS private virtual gateway, configure the IPsec SA to allow ping packets.

Buy Now
Exam Code: 300-440
Exam Name: Designing and Implementing Cloud Connectivity (ENCC)
Last Update: May 18, 2024
Questions: 38

PDF + Testing Engine

$70  $174.99

Testing Engine

$54  $134.99
buy now 300-440 testing engine

PDF (Q&A)

$48  $119.99
buy now 300-440 pdf