Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

300-415 Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Questions 4

How must the application-aware enterprise firewall policies be applied within the same WAN Edge router?

Options:

A.

within and between zones

B.

between two VPN tunnels

C.

within zone pair

D.

between two VRFs

Buy Now
Questions 5

Drag and drop the steps from the left into the order on the right to upload software on vManage repository that is accessible from maintenance > Software Repository.

300-415 Question 5

Options:

Buy Now
Questions 6

How should the IP addresses be assigned for all members of a Cisco vManage cluster located in the same data center?

Options:

A.

in the same subnet

B.

in overlapping IPs

C.

in each controller with a /32 subnet

D.

in different subnets

Buy Now
Questions 7

In a Cisco SD-WAN architecture, what is the role of the WAN Edge?

Options:

A.

It provides orchestration to assist in automatic provisioning of WAN Edge routers and overlay

B.

It is the management plane responsible for centralized configuration and monitoring

C.

It is the control plane that builds and maintains network topology

D.

It is the data plane that is responsible for forwarding traffic

Buy Now
Questions 8

An engineer is applying QoS policy for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router Which command accomplishes the task?

Options:

A.

cloud-qos-service-side

B.

qos-scheduler QOS_0

C.

qos-map QOS

D.

rewrite-rule QOS-REWRITE

Buy Now
Questions 9

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Buy Now
Questions 10

An administrator needs to configure SD-WAN to divert traffic from the company ' s private network to an ISP network. What action should be taken to accomplish this goal?

Options:

A.

configure the control policy

B.

configure the data policy

C.

configure the data security policy

D.

configure the application aware policy

Buy Now
Questions 11

When software is upgraded on a vManage NMS, which two image-adding options store images in a local vManage software repository? (Choose two.)

Options:

A.

To be downloaded over a SMTP connection

B.

To be downloaded over a SNMP connection

C.

To be downloaded over an out-of-band connection

D.

To be downloaded over a control plane connection

E.

To be downloaded over an ICMP connection

Buy Now
Questions 12

300-415 Question 12

Refer to the exhibit. Which configuration extends the INET interface on R1 to be used by R2 for control and data connections?

A)

300-415 Question 12

B)

300-415 Question 12

C)

300-415 Question 12

Options:

A.

Option A

B.

Option B

C.

Option C

Buy Now
Questions 13

An engineer must automate certificate signing through Cisco. Which vManage configuration achieves this task?

A)

300-415 Question 13

B)

300-415 Question 13

C)

300-415 Question 13

D)

300-415 Question 13

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 14

What is the behaviour of vBond orchestrator?

Options:

A.

It maintains vSmart and WAN Edge routers secure connectivity state

B.

it builds permanent connections with vSmart controllers

C.

it updates vSmart of WAN Edge routers behind NAT devices using OMP.

D.

It builds permanent connections with WAN Edge routers

Buy Now
Questions 15

Which command displays BFD session summary information per TLOC on vEdge routers?

Options:

A.

show bfd history

B.

show bfd summary

C.

show bfd sessions

D.

show bfd tloc-summary-list

Buy Now
Questions 16

Refer to the exhibit.

300-415 Question 16

Customer XYZ cannot provison dual connectivity on both Its routers due to budget constratnts but wants to use tnth RI and R2 interface for users behind them for load toward the hub site Which configurauon achieves this objectives?

A)

300-415 Question 16

B)

300-415 Question 16

C)

300-415 Question 16

D)

300-415 Question 16

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 17

Drag and drop the vManage policy configuration procedures from the left onto the correct definitions on the right.

300-415 Question 17

Options:

Buy Now
Questions 18

In a Cisco SD-WAN network, which component is responsible for distributing route and policy information via the OMP?

Options:

A.

vManage

B.

vSmart Controler

C.

vBond Orchestrator

D.

WAN Edge Router

Buy Now
Questions 19

Company ABC has decided to deploy the controllers using the On-Prem method. How does the administrator upload the WAN Edge list to the vManage?

A)

300-415 Question 19

B)

300-415 Question 19

C)

300-415 Question 19

D)

300-415 Question 19

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 20

A customer has MPLS and Internet as the TLOC colors An engineer must configure conlroJIers with the Internet and not with MPLS Which configuration achieves this requirement on vManage?

A)

300-415 Question 20

B)

300-415 Question 20

C)

300-415 Question 20

D)

300-415 Question 20

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 21

Where on vManage does an engineer find the details of control node failure?

Options:

A.

Alarms

B.

Events

C.

Audit log

D.

Network

Buy Now
Questions 22

For data plane resiliency, what does the Cisco SD-WAN software implement?

Options:

A.

BFD

B.

establishing affinity between vSmart controllers and WAN Edge routers

C.

multiple vBond orchestrators

D.

OMP

Buy Now
Questions 23

Which two resource data types are used to collect information for monitoring using REST API in Cisco SD-WAN? (Choose two.)

Options:

A.

POST

B.

DELETE

C.

scalar

D.

array

E.

PUT

Buy Now
Questions 24

Which secure tunnel type should be used to connect one WAN Edge router to other WAN Edge routers?

Options:

A.

TLS

B.

DTLS

C.

SSL VPN

D.

IPsec

Buy Now
Questions 25

Drag and drop the actions from the left into the correct sequence on the right to create a data policy to direct traffic to the Internet exit.

300-415 Question 25

Options:

Buy Now
Questions 26

Which two algorithms authenticate a user when configuring SNMPv3 monitoring on a WAN Edge router? (Choose two.)

Options:

A.

AES-256

B.

SHA-1

C.

AES-128

D.

MD5

E.

SHA-2

Buy Now
Questions 27

A customer wants to use AWS for Cisco SD-WAN laaS services by deploying virtual SD-WAN routers in a transit AWS VPC The transit VPC then connects via site-to-site IPsec tunnels to an AWS transit gateway Which transit VPC connects via site-to-site IPsec tunnels to an AWS transit gateway?

Options:

A.

Cisco Cloud onRamp for Multicloud

B.

Cisco Cloud onRamp for SaaS

C.

Cisco Cloud onRamp for Colocation

D.

Cisco Cloud onRamp for laaS

Buy Now
Questions 28

An engineer must create a QoS policy by creating a class map and assigning it to the LLQ queue on a WAN Edge router Which configuration accomplishes the task?

A)

300-415 Question 28 B)

300-415 Question 28

C)

300-415 Question 28

D)

300-415 Question 28

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 29

Which secure connection should be used to access the REST APIs through the Cisco vManage web server?

Options:

A.

HTTP inspector interface

B.

authenticated HTTPS

C.

authenticated DTLS

D.

JSON Inspector interface

Buy Now
Questions 30

A large retail organization decided to move some of the branch applications to the AWS cloud. How does the network architect extend the in-house Cisco SD-WAN branch to cloud network into AWS?

Options:

A.

Create virtual WAN Edge devices Cloud through the AWS online software store

B.

Create virtual instances of vSmart Cloud through the AWS online software store

C.

Create GRE tunnels to AWS from each branch over the Internet

D.

Install the AWS Cloud Router in the main data center and provide the connectivity from each branch

Buy Now
Questions 31

What is a key element used in a vBond Orchestrator redundancy topology?

Options:

A.

fully qualified domain name

B.

DHCP server

C.

load-balancer with health probes

D.

stun server

Buy Now
Questions 32

In an AWS cloud, which feature provision WAN Edge routers automatically in Cisco SD-WAN?

Options:

A.

Cloud app

B.

Cloud OnRamp

C.

vAnalytics

D.

Network Designer

Buy Now
Questions 33

300-415 Question 33

Refer to the exhibit An engineer must configure a QoS policy between me hub and site A (spoke) over a standard internet circuit where traffic shaping is adjusted automatically based on evaiiabk» bandwidth Which configuration meets the requirement?

300-415 Question 33

300-415 Question 33

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 34

Which type of lists are used to group related items via an application-aware routing policy under the policy lists command hierarchy on vSmart controllers?

Options:

A.

data prefix, she. and VPN

B.

OSCP value, application, and VPN

C.

data prefix, application, and SLA class

D.

DSCP value, site, and VPN

Buy Now
Questions 35

An engineer builds a three-node vManage cluster and then realizes that multiple nodes are unnecessary for the size of the company. How should the engineer revert the setup to a single vManage?

Options:

A.

Remove two rode from the three-node vManage duster

B.

Use the cluster conversion utility lo convert to standalone vManage

C.

Restore vManage from the backup VM snapshot

D.

Leave the duller as & and point to one vManage

Buy Now
Questions 36

What are the default username and password for vSmart Controller when it is installed on a VMware ESXi hypervisor ' ?

Options:

A.

username Cisco password admin

B.

username admin password Cisco

C.

username Cisco password Cisco

D.

username admin password admin

Buy Now
Questions 37

300-415 Question 37

Refer to the exhibit The engineering must assign tags to 3 Of its 74 server networks as soon as they are advertised to peers These server network must not be advertised AS which configuration fulfil the requirement?

A)

300-415 Question 37

B)

300-415 Question 37

C)

300-415 Question 37

D)

300-415 Question 37

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 38

Which service VPN must be reachable from all WAN Edge devices and the controllers?

Options:

A.

VPN0

B.

VPN10

C.

VPN215

D.

VPN512

Buy Now
Questions 39

300-415 Question 39

Refer to the exhibit, which configuration configures IPsec tunnels in active and standby?

300-415 Question 39

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 40

What does forward error correction addresses in Cisco SO-WAN?

Options:

A.

inefficient traffic forwarding caused oy inbound shapers

B.

reduced application performance degradation rotated to service degradation

C.

applications with occasional invalid data input and poor performance

D.

traffic flows with increased delay over a particular transport

Buy Now
Questions 41

Which controller is used for provisioning and configuration in a Cisco SD-WAN solution?

Options:

A.

vBond

B.

Manage

C.

WAN Edge router

D.

vSmart

Buy Now
Questions 42

Which policy blocks TLOCs from remotes and allows TLOCs from the data center to form hub-and-spoke peering?

Options:

A.

localized control policy

B.

localized data policy

C.

centralized data policy

D.

centralized control policy

Buy Now
Questions 43

The Cisco SD-WAN engineer is configuring service chaining for a next-generation firewall located at the headquarters. Which configuration creates the service?

A)

300-415 Question 43

B)

C)300-415 Question 43

300-415 Question 43

D)

300-415 Question 43

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 44

Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?

Options:

A.

OMP outside the DTLS/TLS control connection

B.

BGP inside the DTLS/TLS

C.

IPsec inside the DTLS/TLS control connection

D.

OMP inside the DTLS/TLS control connection

Buy Now
Questions 45

An engineer must configure two branch WAN Edge devices where an Internet connection is available and the controllers are in the headquarters. The requirement is to have IPsec VPN tunnels established between the same colors. Which configuration meets the requirement on both WAN Edge devices?

300-415 Question 45

300-415 Question 45

300-415 Question 45

300-415 Question 45

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 46

Which Cisco SD-WAN component the initial communication between WAN Edge devices to join the fabric?

Options:

A.

WAN Edge Router

B.

vSmart Controller

C.

vManage

D.

vBond Orchestrator

Buy Now
Questions 47

Which Cisco SD-WAN feature propagates packets with SGTs through the network?

Options:

A.

TrustSec Inline Tagging

B.

SGT Enforcement

C.

QoE

D.

SXP

Buy Now
Questions 48

Which policy tracks path characteristics such as loss, latency, and jitter in vManage?

Options:

A.

VPN

B.

control

C.

app-route

D.

data

Buy Now
Questions 49

How is the scalability of the vManage increased in Cisco SD-WAN Fabric?

Options:

A.

Increase licensing on the vManage

B.

Deploy multiple vManage controllers in a cluster

C.

Deploy more than one vManage controllers on different physical server.

D.

Increase the bandwidth of the WAN link connected to the vManage

Buy Now
Questions 50

Which two mechanisms are used by vManage to ensure that the certificate serial number of the WAN Edge router that is needed to authenticate is listed in the WAN Edge Authorized Señal Number Hst’ (Choose two)

Options:

A.

Synchronize to the PnP

B.

Manually upload it to vManage

C.

The devices register to vManage directly as the devices come online

D.

The vManage is shipped with the list

E.

Synchronize to the Smart Account

Buy Now
Questions 51

An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router ' s local site and then change the DSCP value to DSCP 18 before sending it over to the SD-WAN fabric. What are the two ways to create the required configuration? (Choose two).

300-415 Question 51

300-415 Question 51

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Buy Now
Questions 52

A network administrator is configuring a tunnel interface on a branch Cisco IOS XE router to run TLOC extensions. Which configuration will extend a TLOC over a GRE tunnel to another router in the branch?

300-415 Question 52

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 53

Which feature builds transport redundancy by using the cross link between two redundant WAN Edge routers?

Options:

A.

OMP

B.

zero-touch provisioning

C.

quality of service

D.

TLOC extension

Buy Now
Questions 54

What is the ZTP workflow for Cisco IOS XE-based devices?

300-415 Question 54

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 55

Which protocol is used between redundant vSmart controllers to establish a permanent communication channel?

Options:

A.

IPsec

B.

HTTPs

C.

DTLS

D.

SSL

Buy Now
Questions 56

Which set of elements are verified by the controller to confirm the identity of edge devices?

Options:

A.

certificates, organization name and serial number of the device

B.

organization name serial number and system IP of the device

C.

certificates, organization name, and vBond domain

D.

certificates, system IP, and vBond domain

Buy Now
Questions 57

Which command verifies a policy that has been pushed to the vEdge router?

Options:

A.

vEdge# show running-config data policy

B.

vEdge# show policy from-vsmart

C.

vSmart# show running-config policy

D.

vSmart# show running-config apply-policy

Buy Now
Questions 58

What is the function of colocation in Cloud OnRamp SaaS?

Options:

A.

Cloud OnRamp incorporates regional colocation facilities by choosing between cloud access points at the remote site and regional cloud access points at the colocation facilities.

B.

The Cloud OnRamp for colocation solution restricts the creation of different VNF service chains orchestrated in Cisco vManage and deployed on a cluster in a colocation facility.

C.

In Cloud OnRamp. colocation supports the capability of virtualizing access-only locations and using colocation centers that require the customer to extend to the cloud.

D.

With colocation facility in Cloud OnRamp. the customer faces challenges to virtualize the security and optimization infrastructure that influence traffic through network elements.

Buy Now
Questions 59

300-415 Question 59

Refer to the exhibit Cisco SD-WAN is deployed with controllers hosted in a data center All branches have WAN Edge devices with dual connections to the data center one via Internet and the other using MPLS Three branches out of 20 have issues with their control connections on MPLS circuit The local error refers to Control Connection Failure Which action resolves the issue*?

Options:

A.

Rectify any issues with the underlay routing configuration

B.

Match the TLOC color on the controllers and all WAN Edge devices

C.

Match certificates for the DTLS connection and Root CA must be installed first on WAN Edge devices

D.

Update the system IP on vManage and then resend it to the controllers

Buy Now
Questions 60

Which two mechanisms are used to guarantee the integrity of data packets in the Cisco SD-WAN architecture data plane? {Choose two)

Options:

A.

transport locations

B.

authentication headers

C.

certificates

D.

TPM chip

E.

encapsulation security payload

Buy Now
Questions 61

An engineer modifies a data policy for DIA in VPN 200 to meet the requirements for traffic destined to these locations:

* external networks; must be translated

* external networks; must use a public TLOC color

* syslog servers, must use a private TLOC color

Here is the existing data policy configuration:

300-415 Question 61

Which policy configuration sequence set meets the requirements?

Options:

A.
B.
C.
Buy Now
Questions 62

Which configuration changes the packet loss priority from low to highly?

A)

300-415 Question 62

B)

300-415 Question 62

C)

300-415 Question 62

D)

300-415 Question 62

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 63

300-415 Question 63

Refer to the exhibit. Which configuration stops Netconf CLI logging on WAN Edge devices during migration?

300-415 Question 63

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 64

How many cloud gateway instance(s) can be created per region when provisioning Cloud OnRamp for Multicloud from AWS in a multiregion environment?

Options:

A.

one

B.

two

C.

three

D.

four

Buy Now
Questions 65

Which protocol is used to measure jitter, loss, and latency on SD-WAN overlay tunnels?

Options:

A.

QoE

B.

OMP

C.

BGP

D.

BFD

Buy Now
Questions 66

300-415 Question 66

An engineer configures Rome WAN Edge 10 use MPLS cloud as the preferred link to reach Paris WAN Edge and use biz-internet as a backup. Which policy configuration must be led in the outbound direction toward Rome to accomplish the task?

A)

300-415 Question 66

B)

300-415 Question 66

C)

300-415 Question 66

D)

300-415 Question 66

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 67

Drag and drop the BFD parameters from the left onto the BFD configurations on the right.

300-415 Question 67

Options:

Buy Now
Questions 68

An SD-WAN customer must ensure that its network operations team can monitor and update the NTP server if needed on a WAN Edge in HQ. Which configuration meets this requirement?

Options:

A.

system

usergroup operator

task interface write

B.

system

aaa

usergroup operator

task policy write

C.

system

aaa

usergroup operator

task system write

D.

system

aaa

usergroup operator

task security write

Buy Now
Questions 69

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.

Cloud Services Platform

B.

VNF Service Chaning

C.

Cloud onRamp for Colocation

D.

Cloud onRamp for laaS

Buy Now
Questions 70

When the VPN membership policy is being controlled at the vSmart controller, which policy disallows VPN 1 at sites 20 and 30?

A)

300-415 Question 70

B)

300-415 Question 70

C)

300-415 Question 70

D)

300-415 Question 70

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 71

An engineer is configuring a WAN Edge router for DIA based on matching QoS parameters. Which two actions accomplish this task? (Choose two.)

Options:

A.

Apply a QoS map policy.

B.

Configure a control policy.

C.

Configure a centralized data policy.

D.

Configure NAT on the transport interface.

E.

Apply a data policy on WAN interface.

Buy Now
Questions 72

An engineer must configure local redundancy on a site. Which configuration accomplish this task?

Options:

A.

vpn 0interface interface-name

B.

tloc extension interlace nametloc extension interface interface name

C.

vpn 0tloc extension interface

D.

interface-flameinterface interface-name tloc-extension

Buy Now
Questions 73

Refer to exhibit. An engineer is troubleshooting tear of control connection even though a valid CertificateSerialNumber is entered. Which two actions resolve Issue? (Choose two)

300-415 Question 73

Options:

A.

Restore network reachability on the controller.

B.

Enter a valid serial cumber on the controller for a given device

C.

Enter a valid product ID (mode) on the PNP portal.

D.

Match the serial number file between the controller

E.

Remove the duplicate IP in the network

Buy Now
Questions 74

What is a default protocol for control plane connection?

Options:

A.

IPsec

B.

HTTPS

C.

TLS

D.

DTLS

Buy Now
Questions 75

When a WAN Edge device joins the SD-WAN overlay, which Cisco SD-WAN components orchestrates the connection between the WAN Edge device and a vSmart controller?

Options:

A.

vManage

B.

vBond

C.

OMP

D.

APIC-EM

Buy Now
Questions 76

Drag and drop the policies from the left onto the correct policy types on the right.

300-415 Question 76

Options:

Buy Now
Questions 77

Exhibit.

300-415 Question 77

The SD-WAN network Is configured with a default full-mesh topology. The network engineer wants the Rome WAN Edge to use the MPLS TLOC as the preferred TLOC when ….. Telnet traffic as long as me MPLS Ink has these, characteristics:

Loss: 5%

Latency: 100ms

Jitter: 100 ms

Which configuration must the network engineer use to create a list that that classifies the MPLS link characteristics?

A)

300-415 Question 77

B)

300-415 Question 77

C)

300-415 Question 77

D)

300-415 Question 77

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Buy Now
Questions 78

In the Cisco SD_WAN solution, vSmart controller is responsible for which two actions? (Choose two.)

Options:

A.

Distribute crypto key information among vEdge routers

B.

Configure and monitor vEdge routers.

C.

Authenticate and authorize vEdge routers.

D.

Distribute the IP address from DHCP server to vEdge routers.

E.

Distribute route and policy information via OMP.

Buy Now
Questions 79

What is a benefit of the application aware firewall feature in the Cisco SD-WAN solution?

Options:

A.

application monitoring

B.

application malware protection

C.

application visibility

D.

control policy enforcement

Buy Now
Questions 80

What is an attribute of TLOC’?

Options:

A.

encryption

B.

local preference

C.

tag

D.

service

Buy Now
Questions 81

Refer to the exhibit.

300-415 Question 81

The control connection is failing. Which action resolves the issue?

Options:

A.

import vSmart in vManager

B.

Validate the certificates authenticity on vSmart

C.

Upload the WAN Edge list on vManage.

D.

Restore the reachability to the vSmart

Buy Now
Questions 82

300-415 Question 82

Refer to the exhibit. An enterprise network is connected with an ISP network on an 80 Mbps bandwidth link. The network operation team observes 100 Mbps traffic on the 1Gig-ISP link during peak hours Which configuration provides bandwidth control to avoid traffic congestion during peak hours?

A)

300-415 Question 82

B)

300-415 Question 82

C)

300-415 Question 82

D)

300-415 Question 82

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 83

Which configuration defines the groups of interest before creation of the access list or route map?

A)

300-415 Question 83

B)

300-415 Question 83

C)

300-415 Question 83

D.

300-415 Question 83

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 84

How does the Cisco SD-WAN Cloud OnRamp solution rate the performance of a SaaS application from a branch office to the cloud via a given path?

Options:

A.

It computes a quality-of-experience score.

B.

It monitors the packet loss of priority queues.

C.

It counts the number of interface errors.

D.

It measures the delay and jitter of the path.

Buy Now
Questions 85

Which two products are used to deploy Cisco WAN Edge Router virtual platforms? (Choose two.)

Options:

A.

HP ProLiant DL360 Generatton10 running HP-UX

B.

Cisco ENCS 5000 Series

C.

Sun SPARC Node running AIX

D.

Cisco UCS

E.

Sun Enterprise M4000 Server running Sun Solans

Buy Now
Questions 86

Drag and drop the devices from the left into order on the right to upgrade the software from version 19 to version 20.

300-415 Question 86

Options:

Buy Now
Questions 87

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the master device. What must be configured to get the fastest failover to standby?

Options:

A.

lower timer interval

B.

prefix-list tracking

C.

higher group ID number

D.

OMP tracking

Buy Now
Questions 88

Which policy allows communication between TLOCs of data centers and spokes and blocks communication between spokes?

Options:

A.

centralized data policy

B.

centralized control policy

C.

localized control policy

D.

localized data policy

Buy Now
Questions 89

What is a benefit of the application-aware firewall?

Options:

A.

It blocks traffic by MAC address

B.

It blocks traffic by MTU of the packet.

C.

It blocks traffic by application.

D.

It blocks encrypted traffic

Buy Now
Questions 90

Which two protocols are supported for software image delivery when images are hosted on a remote server? (Choose two.)

Options:

A.

HTTPS

B.

SSL

C.

HTTP

D.

TFTP

E.

FTP

Buy Now
Questions 91

Which two requirements must be met for DNS inspection when integrating with cisco umbrella? (Choose two)

Options:

A.

Upload the WAN Edge serial allow list to the Umbrella portal.

B.

Attach security policy to the device template.

C.

Configure the Umbrella token on the vManage

D.

Create and attach a System feature template with the Umbrella registration credentials.

E.

Register and configure the vManage public IP and serial number in the Umbrella portal.

Buy Now
Questions 92

Which device information is requited on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.

serial and chassis numbers

B.

interface IP address

C.

public DNS entry

D.

system IP address

Buy Now
Questions 93

Refer to the exhibit.

300-415 Question 93

300-415 Question 93

An engineer is troubleshooting an issue where vManage and vSmart have a problem establishing a connection to vBond. Which action fixes the issue?

Options:

A.

Reconfigure the vBond command on the vBond as vBond 150.5.1.3 local

B.

Configure the tunnel interface on all three controllers with a color of transport

C.

Remove the encapsulation IPsec command under the tunnel interface of vBond.

D.

Configure encapsulation as IPsec under the tunnel interface of vManage and vSmart

Buy Now
Questions 94

Which two advanced security features are available on the Cisco SD-WAN WAN Edge (vEdge) device? (Choose two.)

Options:

A.

URL filtering

B.

snort intrusion prevention system

C.

Cisco Umbrella DNS Security

D.

Cisco AMP and AMP Threat Grid

E.

Enterprise Firewall

Buy Now
Questions 95

Which IP address must be reachable by a WAN Edge device for the ZIP process to work?

Options:

A.

10.1.1.1

B.

4.4 4.4

C.

172.16.1.1

D.

8.8.8.8

Buy Now
Questions 96

How are custom application ports monitored in Cisco SD-WAN controllers?

Options:

A.

Customers add custom application ports in vAnalytics and vManage.

B.

Customers add custom application ports in vAnalytics and vSmart.

C.

Cisco adds custom application ports In vAnalytics and vManage.

D.

Cisco adds custom application ports In vAnalytics and vSmart.

Buy Now
Questions 97

How is an event monitored and reported for an individual device in the overlay network at site ID:S4300T6E43F36?

Options:

A.

The device sends event notifications to vManage.

B.

The device sends notifications to vSmart that sends them to vManage.

C.

The device sends a critical alarm of events to vManage.

D.

The device sends a critical alarm to vSmart that sends it to vManage.

Buy Now
Questions 98

Which routing protocol is used to exchange control plane information between vSmart controllers and WAN Edge routers in the Cisco SD-WAN secure extensible network?

Options:

A.

BGP

B.

OSPF

C.

BFD

D.

OMP

Buy Now
Questions 99

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Options:

A.

A domain is nonexistent.

B.

A domain is block-listed.

C.

A domain is locally reachable.

D.

A domain is grey-listed.

Buy Now
Questions 100

300-415 Question 100

Refer to the exhibit. An engineer is enabling command line access via MPLS for in-band management. Which command completes the partial SD-WAN interface configuration with the highest degree of security?

300-415 Question 100

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 101

Which two criteria ate supported to filter traffic on a Cisco Umbrella Cloud-delivered firewall? (Choose two )

Options:

A.

tunnels

B.

site ID

C.

URL

D.

geolocation

E.

protocol

Buy Now
Questions 102

An engineer is adding a tenant with location ID 399533345 in vManage. What is the maximum number of alphanumeric characters that is accepted in the tenant name filed?

Options:

A.

64

B.

128

C.

256

D.

8

Buy Now
Questions 103

Which feature delivers traffic to the Cisco Umbrella SIG cloud from a Cisco SD-WAN domain?

Options:

A.

L2TPv3 tunnel

B.

IPsec tunnel

C.

local umbrella agent

D.

source NAT

Buy Now
Questions 104

What is the function of the AppNav Controller in the Cisco SD-WAN AppNav solution?

Options:

A.

It accelerates specific traffic based on preconfigured policies.

B.

It provides information about configured optimization policies on SD-WAN edge devices.

C.

It provides configuration and monitoring for WAAS nodes.

D.

It intercepts and distributes network traffic based on configured policies.

Buy Now
Questions 105

300-415 Question 105

Refer to the exhibit Which configuration ensures that OSPF routes learned from Site2 are reachable at Sitel and vice-versa?

300-415 Question 105

300-415 Question 105

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 106

Which type of route advertisement of OMP can be verified?

Options:

A.

OMP, VPN. and origin

B.

Origin, TLOC, and VPN

C.

Origin, TLOC, and service

D.

OMP, TLOC and service

Buy Now
Questions 107

An engineer must deploy a QoS policy with these requirements:

• policy name: App-police

• police rate: 1000000

• burst: 1000000

• exceed: drop

Which configuration meets the requirements?

300-415 Question 107

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 108

300-415 Question 108

Refer to the exhibit. An engineer configures a hub-and-spoke SD-WAN topology with the requirement that traffic from router A branch to router B branch is guaranteed to flow through the network hub, router C. Which configuration meets the requirement for router A?

300-415 Question 108

300-415 Question 108

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 109

300-415 Question 109

Refer to the exhibit. An engineer must block FTP traffic coming in from a particular Service VPN on a WAN Edge device Which set of steps achieves this goal?

Options:

A.

Create a localized policy and add it to (he interface feature template

B.

Create a localized policy add it to the device template and add an ACL to the interface feature template

C.

Create a prefix tat, add it to the localized policy and add it to the interface feature template

D.

Create a localized policy add it to VPN template and add an ACL to the interface feature template

Buy Now
Questions 110

Which action is performed during the onboarding process when a WAN Edge router is connected to ZTP server ztp.viptela com?

Options:

A.

The router is connected to WAN Edge Cloud Center

B.

The router is synced with vSmart Controller via an IPsec tunnel

C.

The router receives its vBond Orchestrator information

D.

The router is connected 10 vSmart Controller via a DTLSTLS tunnel

Buy Now
Questions 111

Refer to the exhibit.

300-415 Question 111

Which shaping-rate does the engineer use to shape traffic at 9 Mbps?

Options:

A.

9

B.

9000

C.

90000

D.

9000000

Buy Now
Questions 112

An organization wants to discover monitor and track the applications running on the WAN Edge device on the LAN Which configuration achieves this goal?

300-415 Question 112

300-415 Question 112

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 113

An enterprise deployed a Cisco SD-WAN solution with hub-and-spoke topology using MPLS as the preferred network over the Internet. A network engineer must implement an application-aware routing policy to allow ICMP traffic to be load-balanced over both the available links. Which configuration meets the requirement?

A)

300-415 Question 113

B)

300-415 Question 113

C)

300-415 Question 113

D)

300-415 Question 113

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 114

300-415 Question 114

300-415 Question 114

300-415 Question 114

Refer to the exhibit A small company was acquired by a large organization As a result, the new organization decided to update information on their Enterprise RootCA and generated a new certificate using openssl Which configuration updates the new certificate and issues an alert in vManage Monitor | Events Dashboard?

300-415 Question 114

300-415 Question 114

300-415 Question 114

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 115

Refer to the exhibit.

300-415 Question 115

Which QoS treatment results from this configuration after the access list acl-guest is applied inbound on the vpn1 interface?

Options:

A.

A UDP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

B.

A TCP packet sourcing from 172.16.10.1 and destined to 172.16.20.1 is dropped

C.

A UDP packet souring from 172.16.10.1 and destined to 172.16.20.1 is dropped.

D.

A TCP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

Buy Now
Questions 116

An enterprise is continuously adding new sites to its Cisco SD-WAN network. It must configure any cached routes flushed when OMP peers have lost adjacency Which configuration allows the cached OMP routes to be flushed after every 24 hours from its routing table?

300-415 Question 116

300-415 Question 116

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 117

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?

Options:

A.

APIC-EM

B.

vSmart

C.

vManage

D.

vBond

Buy Now
Questions 118

A network administrator is configuring an application-aware firewall between inside zones to an outside zone on a WAN edge router using vManage GUI. What kind of Inspection is performed when the ‘’inspect’’ action is used?

Options:

A.

stateful inspection for TCP and UDP

B.

stateful inspection for TCP and stateless inspection of UDP

C.

IPS inspection for TCP and-Layer 4 inspection for UDP

D.

Layer 7 inspection for TCP and Layer 4 inspection for UDP

Buy Now
Questions 119

Which website allows access to visualize the geography screen from vManager using the internet?

Options:

A.

*.opcnstreetmaps.org

B.

*.fullstreetmaps.org

C.

*.callstreelmaps.org

D.

*.globaistreetmaps.org

Buy Now
Questions 120

Which Cisco router provides a distributed multicore architecture optimized for SD-WAN branch support?

Options:

A.

Cisco 1000 ISR series

B.

Cisco 2900 ISR series

C.

Cisco Catalyst 3850 series

D.

Cisco 3900 ISR series

Buy Now
Questions 121

What is a requirement for a WAN Edge to reach vManage, vBond, and vSmart controllers in a data center?

Options:

A.

IGP

B.

QoS

C.

TLS

D.

OMP

Buy Now
Questions 122

Which encryption algorithm is used for encrypting SD-WAN data plane traffic?

Options:

A.

Triple DES

B.

IPsec

C.

AES-128

D.

AES-256 GCM

Buy Now
Questions 123

Which timer specifies information in the cache after all OMP sessions are lost at location S0123T4E56F78?

Options:

A.

advertisement interval

B.

EOR timer

C.

graceful restart timer

D.

hold time

Buy Now
Questions 124

A company deploys a Cisco SD-WAN solution but has an unstable Internet connection. When the link to vSmart comes back up, the WAN Edge router routing table is not refreshed, and some traffic to the destination network is dropped. The headquarters is the hub site, and it continuously adds new sites to the SD-WAN network. An engineer must configure route refresh between WAN Edge and vSmart within 2 minutes. Which configuration meets this requirement?

300-415 Question 124

Options:

A.

Option A

B.

B

C.

Option B

D.
E.

Option C

F.

Option D

Buy Now
Questions 125

An administrator is configuring the severity level on the vManage NMS for events that indicate that an action must be taken immediately. Which severity level must be configured?

Options:

A.

warning

B.

error

C.

critical

D.

alert

Buy Now
Questions 126

What prohibits deleting a VNF image from the software repository?

Options:

A.

if the image is stored by vManage

B.

if the image is referenced by a service chain

C.

if the image is uploaded by a WAN Edge device

D.

if the image is included in a configured policy

Buy Now
Questions 127

An engineer is configuring a data policy IPv4 prefixes for a site WAN edge device on a site with edge devices. How is this policy added using the policy configuration wizard?

Options:

A.

In vManage NMS select (he configure ► policies screen, select the centralized policy tab and click add policy

B.

In vBood orchestrator. select the configure > policies screen select the localized policy tab. and click add policy

C.

In vManage NMS. select the configure ► policies screen. select the localized policy tab- and click add policy

D.

In vSmart controller select tie configure ► policies screen, select the localized policy tab, and click add policy

Buy Now
Questions 128

An engineering team must prepare a traffic engineering policy where an MPLS circuit is preferred for traffic coming from the Admin VLAN Internet should be used as a backup only. Which configuration fulfill this requirement?

A)

300-415 Question 128

B)

300-415 Question 128

C)

300-415 Question 128

D)

300-415 Question 128

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 129

Drag and drop the alarm states from the left onto the corresponding alarm descriptions on the right.

300-415 Question 129

Options:

Buy Now
Questions 130

Which two products that perform lifecycle management for virtual instances are supported by WAN Edge cloud routers? (Choose two.)

Options:

A.

OpenStack

B.

AWS

C.

VMware vCenter

D.

Azure

E.

IBM Cloud

Buy Now
Questions 131

An engineer wants to automate the onboarding process for a WAN Edge router with vManage. Which command will accomplish this?

Options:

A.

request vedge-cloud activate chassis-number < chassis-number > serial < serial >

B.

request vedge-cloud activate chassis-number < chassis-number > token < token-number >

C.

request vedge-cloud activate serial < serial > token < token-number >

D.

request vedge-cloud activate chassis-number < chassis-number > organization < organization >

Buy Now
Questions 132

Which two sets of identifiers does OMP carry when it advertises TLOC routes between WAN Edge routers? (Choose two.)

Options:

A.

TLOC public and private address, carrier, and preference

B.

source and destination IP address, MAC, and site ID

C.

system IP address, link color, and encapsulation

D.

VPN ID, local site network, and BGP next-hop IP address

E.

TLOC public and private address, tunnel ID, and performance

Buy Now
Questions 133

When redistribution is configured between OMP and BGP at two Data Center sites that have Direct Connection interlink, which step avoids learning the same routes on WAN Edge routers of the DCs from LAN?

Options:

A.

Define different VRFs on both DCs

B.

Set same overlay AS on both DC WAN Edge routers

C.

Set down-bit on Edge routers on DC1

D.

Set OMP admin distance lower than BGP admin distance

Buy Now
Exam Code: 300-415
Exam Name: Implementing Cisco SD-WAN Solutions (300-415 ENSDWI)
Last Update: May 25, 2026
Questions: 446

PDF + Testing Engine

$65.27   $186.49

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11