Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

300-415 Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Questions 4

Drag and drop the steps from the left into the order on the right to delete a software image for a WAN Edge router starting with Maintenance > Software Upgrade > Device list on vManage.

300-415 Question 4

Options:

Buy Now
Questions 5

How many cloud gateway instance(s) can be created per region when provisioning Cloud OnRamp for Multicloud from AWS in a multiregion environment?

Options:

A.

one

B.

two

C.

three

D.

four

Buy Now
Questions 6

Which on-the-box security feature supported by the Cisco ISR 4451 SD-WAN device and not on vEdge?

Options:

A.

Cloud Express service

B.

Enterprise Firewall with Application Awareness

C.

reverse proxy

D.

IPsec/GRE cloud proxy

Buy Now
Questions 7

Which SD-WAN component allows an administrator to manage and store software images for SD-WAN network elements?

Options:

A.

vGond controllers

B.

WAN Edge routers

C.

vSman controllers

D.

vManage NMS

Buy Now
Questions 8

Drag and drop the alarm slates from the left onto the corresponding alarm descriptions on the right.

300-415 Question 8

Options:

Buy Now
Questions 9

What two functions describe the TCP optimization tool used in the Cisco SD-WAN? (Choose two.)

Options:

A.

It uses TCP acknowledgment (ACK).

B.

It is used to take care of high packet loss for control traffic.

C.

It terminates TCP connections locally at the WAN edge.

D.

It uses TCP selective acknowledgment (SACK).

E.

It terminates TCP connections at the remote WAN edge.

Buy Now
Questions 10

A policy is created to influence routing in the network using a group of prefixes. What policy application will achieve this goal when applied to a site list?

Options:

A.

Vpn-membership policy

B.

Control-policy

C.

cflowd-template

D.

App-route policy

Buy Now
Questions 11

What does forward error correction addresses in Cisco SO-WAN?

Options:

A.

inefficient traffic forwarding caused oy inbound shapers

B.

reduced application performance degradation rotated to service degradation

C.

applications with occasional invalid data input and poor performance

D.

traffic flows with increased delay over a particular transport

Buy Now
Questions 12

Which Cisco SD-WAN WAN Edge platform supports LTE and Wi-Fi?

Options:

A.

vEdge2000

B.

ASR1001

C.

CSR 1000v

D.

ISR 1101

Buy Now
Questions 13

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Options:

A.

A domain is nonexistent.

B.

A domain is block-listed.

C.

A domain is locally reachable.

D.

A domain is grey-listed.

Buy Now
Questions 14

How must the application-aware enterprise firewall policies be applied within the same WAN Edge router?

Options:

A.

within and between zones

B.

between two VPN tunnels

C.

within zone pair

D.

between two VRFs

Buy Now
Questions 15

A network administrator is creating an OMP feature template from the vManage GUI to be applied to WAN edge routers. Which configuration attribute will avoid the redistribution of the routes back into the OMP from the LAN side?

Options:

A.

configure "Number of Paths Advertised per Prefix"

B.

configure "Overlay AS Number"

C.

configure "Send Backup Paths"

D.

configure "ECMP limit"

Buy Now
Questions 16

What is the default value for the number of paths advertised per prefix in the OMP feature template?

Options:

A.

4

B.

8

C.

12

D.

16

Buy Now
Questions 17

Refer to the exhibit.

300-415 Question 17

An engineer is configuring service chaining. Which set of configurations is required for all traffic from Site ID 1 going toward Site ID 2 to get filtered through the firewall on the hub site?

A)

300-415 Question 17

B)

300-415 Question 17

C)

300-415 Question 17

D)

300-415 Question 17

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 18

Which platform is a Cisco SD-WAN virtual platform?

Options:

A.

Cisco ISR 4000

B.

Cisco Nexus 1000V

C.

Cisco CSR 1000V

D.

Cisco ASR 1000

Buy Now
Questions 19

Which two architectural components are part of an SD-WAN high availability vManage cluster? (Choose two.)

Options:

A.

WAN Edge router

B.

network configuration system

C.

NAT router

D.

messaging server

E.

application server

Buy Now
Questions 20

What is the advantage of instating the controller on-premises?

Options:

A.

ease of deployment and management

B.

full control of the data piano and the control plane

C.

automatic geographical redundancy and security

D.

scalability and a cost-saving

Buy Now
Questions 21

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop malicious attachments before they reach users and get executed. Which Cisco SD-WAN solution meets the requirements?

Options:

A.

Cisco Trust Anchor module

B.

URL filtering and Umbrella DNS security

C.

Cisco AMP and Threat Grid

D.

Snort IPS

Buy Now
Questions 22

Which Cisco SD-WAN feature propagates packets with SGTs through the network?

Options:

A.

TrustSec Inline Tagging

B.

SGT Enforcement

C.

QoE

D.

SXP

Buy Now
Questions 23

300-415 Question 23

Refer to the exhibit Which configuration must the engineer use to form underlay connectivity for the Cisco SD-WAN network?

A)

300-415 Question 23

B)

300-415 Question 23

C)

300-415 Question 23

D)

300-415 Question 23

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 24

A vEdge platform is sending VRRP advertisement messages every 10 seconds. Which value configures the router back to the default timer?

Options:

A.

2 seconds

B.

3 seconds

C.

1 second

D.

5 seconds

Buy Now
Questions 25

Refer to the exhibit.

300-415 Question 25

Which configuration change is needed to configure the tloc-extention on Branch1-Edge1?

300-415 Question 25

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 26

Which configuration allows users to reach YouTube from a local Internet breakout?

A)

300-415 Question 26

B)

300-415 Question 26

C)

300-415 Question 26

D)

300-415 Question 26

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 27

An engineer is configuring a WAN Edge router for DIA based on matching QoS parameters. Which two actions accomplish this task? (Choose two.)

Options:

A.

Apply a QoS map policy.

B.

Configure a control policy.

C.

Configure a centralized data policy.

D.

Configure NAT on the transport interface.

E.

Apply a data policy on WAN interface.

Buy Now
Questions 28

300-415 Question 28

300-415 Question 28

Refer to the exhibit vManage and vBond have an issue establishing a connection with each other Which action resolves the issue?

Options:

A.

Reconfigure the system IPs to belong to the same subnet

B.

Change the organization name on both controllers to match vipteta.com.

C.

Remove the encapsulation ipsec command under the tunnel interface of vBond

D.

Configure the encapsulation ipsec command under the tunnel interface on vManage

Buy Now
Questions 29

What is the order of operations for software upgrades of Cisco SD-WAN nodes'?

Options:

A.

vBond vManage vSmart WAN Edge

B.

vManage vBond WAN Edge. vSmart

C.

vManage vSmart, vBond, WAN Edge

D.

vManage vBond vSraart WAN Edge

Buy Now
Questions 30

Drag and drop the components from the left onto the corresponding Cisco NFV infrastructure Building Blocks on the right. Not all options are used.

300-415 Question 30

Options:

Buy Now
Questions 31

Which two criteria ate supported to filter traffic on a Cisco Umbrella Cloud-delivered firewall? (Choose two )

Options:

A.

tunnels

B.

site ID

C.

URL

D.

geolocation

E.

protocol

Buy Now
Questions 32

Which protocol Is used by the REST API to communicate with network services in the Cisco SO-WAN network?

Options:

A.

SSL

B.

HTTP

C.

iPsec

D.

SSM

Buy Now
Questions 33

Which protocol is used to measure loss latency, Jitter, and liveliness of the tunnel between WAN Edge router peers?

Options:

A.

OMP

B.

IP SLA

C.

NetFlow

D.

BFD

Buy Now
Questions 34

For data plane resiliency, what does the Cisco SD-WAN software implement?

Options:

A.

BFD

B.

establishing affinity between vSmart controllers and WAN Edge routers

C.

multiple vBond orchestrators

D.

OMP

Buy Now
Questions 35

An engineer is applying QoS policy for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router Which command accomplishes the task?

Options:

A.

cloud-qos-service-side

B.

qos-scheduler QOS_0

C.

qos-map QOS

D.

rewrite-rule QOS-REWRITE

Buy Now
Questions 36

Where on vManage does an engineer find the details of control node failure?

Options:

A.

Alarms

B.

Events

C.

Audit log

D.

Network

Buy Now
Questions 37

300-415 Question 37

Refer to the exhibit Which configuration ensures that OSPF routes learned from Site2 are reachable at Sitel and vice-versa?

300-415 Question 37

300-415 Question 37

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 38

Which device information is required on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.

interface IP address

B.

system IP address

C.

public DNS entry

D.

serial and chassis numbers

Buy Now
Questions 39

Which OMP route is selected for equal OMP route preference values on WAN Edge routers?

Options:

A.

route with higher TLOC preference value

B.

route with origin type of connected

C.

route with origin type of static

D.

route with lower TLOC preference value

Buy Now
Questions 40

Which two virtualized environments are available for a company to install the controllers using the on-premises model? (Choose two )

Options:

A.

VMware vSphere ESXi

B.

VMware Workstation

C.

kernel-based virtual machine

D.

OpenStack

E.

Microsoft Hyper-V

Buy Now
Questions 41

300-415 Question 41

Refer to the exhibit The network team must configure ElGRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

300-415 Question 41

Which configuration on the WAN Edge meets the requiremnet

A)

300-415 Question 41

B)

300-415 Question 41

C)

300-415 Question 41

D)

300-415 Question 41

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 42

An engineer is configuring a list that matches all IP prefixes with lengths from /1 to /16 in a centralized control policy. Which list accomplishes this task?

Options:

A.

0.0.0.0/1 le 16

B.

0.0.0.0/0 ge 1

C.

0.0.0.0/0 le l6

D.

0.0.0.0/16 ge 1

Buy Now
Questions 43

Which cloud based component in cisco SD-WAN is responsible for establishing a secure connection to each WAN edge router and distributes routers and policy information via omp?

Options:

A.

vBond

B.

vManage

C.

vSmart

D.

WAN Edge

Buy Now
Questions 44

A network administrator configures SNMPv3 on a Cisco WAN Edge router from CLI for monitoring purposes How many characters are supported by the snmp user <username> command?

Options:

A.

from 1 to 8

B.

from 1 to 16

C.

from 1 to 32

D.

from 1 to 48

Buy Now
Questions 45

300-415 Question 45

Refer to the exhibit An engineer is configuring a QoS policy to shape traffic for VLAN 100 on a subinterface Which policy configuration accomplishes the task?

A)

300-415 Question 45

B)

300-415 Question 45

C)

300-415 Question 45

D)

300-415 Question 45

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 46

An engineer is configuring a data policy for IPv4 prefixes for a single WAN Edge device on a site with multiple WAN Edge devices How is this policy added using the policy configuration wizard?

Options:

A.

ln vManage NMS, select the configure â–º policies screen, select the localized policy tab and click add policy

B.

In vSmart controller, select the configure â–º policies screen, select the localized policy tab. and click add policy

C.

In vManage NMS. select the configure â–º policies screen select the centralized policy tab and click add policy

D.

In vBond orchestrator. select the configure â–º policies screen, select the localized policy tab. and click add policy

Buy Now
Questions 47

Which control policy assigned to Drenches in the out direction establishes a strict hub-and-spoke topology tor VPN2?

A)

300-415 Question 47

B)

300-415 Question 47

C)

300-415 Question 47

D)

300-415 Question 47

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Buy Now
Questions 48

Drag and drop the vManage policy configuration procedures from the left onto the correct definitions on the right.

300-415 Question 48

Options:

Buy Now
Questions 49

Which Cisco SD-WAN component the initial communication between WAN Edge devices to join the fabric?

Options:

A.

WAN Edge Router

B.

vSmart Controller

C.

vManage

D.

vBond Orchestrator

Buy Now
Questions 50

A large retail organization decided to move some of the branch applications to the AWS cloud. How does the network architect extend the in-house Cisco SD-WAN branch to cloud network into AWS?

Options:

A.

Create virtual WAN Edge devices Cloud through the AWS online software store

B.

Create virtual instances of vSmart Cloud through the AWS online software store

C.

Create GRE tunnels to AWS from each branch over the Internet

D.

Install the AWS Cloud Router in the main data center and provide the connectivity from each branch

Buy Now
Questions 51

What is the minimum Red Hat Enterprise Linux operating system requirement for a Cisco SD-WAN controller deployment via KVM?

Options:

A.

RHEL7.5

B.

RHEL 6.5

C.

RHEL4.4

D.

RHEL 6.7

Buy Now
Questions 52

Which attributes are configured to uniquely Identify and represent a TLOC route?

Options:

A.

system IP address, link color, and encapsulation

B.

firewall, IPS, and application optimization

C.

site ID, tag, and VPN

D.

origin, originator, and preference

Buy Now
Questions 53

A network engineer sets tags in OMP for routes that were originated in the Service VPN. Which monitoring tab must be used to verify tags on the next hop?

Options:

A.

Realtime > OMP Received TLOCs

B.

Troubleshooting > Simulate Flows

C.

Realtime > OMP Received Routes

D.

Troubleshooting > Tunnel Health

Buy Now
Questions 54

300-415 Question 54

Refer to the exhibit Which configuration sets up direct Internet access for VPN 1?

300-415 Question 54

300-415 Question 54

Options:

A.

Option A

B.

Option B

C.

Option C

Buy Now
Questions 55

An engineer must apply the configuration for certificate installation to vBond Orchestrator and vSmart Controller. Which configuration accomplishes this task?

300-415 Question 55

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 56

Which two image formats are supported for controller codes? (Choose two.)

Options:

A.

.nxos

B.

.qcow2

C.

.ova

D.

.bin

E.

Tgz

Buy Now
Questions 57

Refer to the exhibit.

300-415 Question 57

Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)

Options:

A.

Generate a CSR manually within vManage server

B.

Generate a CSR manually on the WAN Edge

C.

Request a certificate manually from the Enterprise CA server

D.

Install the certificate received from the CA server manually on the WAN Edge

E.

Install the certificate received from the CA server manually on the vManage

Buy Now
Questions 58

What is the default value (in milliseconds) set tor the poll interval in the BFD basic configuration?

Options:

A.

300,000

B.

600,000

C.

900,000

D.

1,200,000

Buy Now
Questions 59

A network administrator is tasked to make sure that an OMP peer session is closed after missing three consecutive keepalive messages in 3 minutes. Additionally, route updates must be sent every minute. If a WAN Edge router becomes unavailable, the peer must use last known information to forward packets for 12 hours. Which set of configuration commands accomplishes this task?

300-415 Question 59

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 60

An engineer wants to change the configuration of the certificate authorization mode from manual to automated. Which GUI selection will accomplish this?

Options:

A.

Maintenance > Security

B.

Configuration > Certificates

C.

Administration > Settings

D.

Tools > Operational Commands

Buy Now
Questions 61

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?

Options:

A.

APIC-EM

B.

vSmart

C.

vManage

D.

vBond

Buy Now
Questions 62

In which Cisco SD-WAN deployment scenario does Cisco Umbrella SIG deliver the most value?

Options:

A.

when a centralized Internet breakout solution is implemented

B.

when resource-intensive security operations are offloaded from entry-level WAN Edge devices

C.

when the identity of several WAN Edge devices is verified throughout the networkthroughout the network

Buy Now
Questions 63

What is a benefit of using REST APIs?

Options:

A.

predefined automation and orchestration platform for event management and logging

B.

user-defined automation and integration into other orchestration systems or tools

C.

vAnalytics to simplify operational services integration and real-time event monitoring

D.

predefined SD-WAN controller with other platform integration for event management and logging

Buy Now
Questions 64

Refer to the exhibit.

300-415 Question 64

A customer wants to implement primary and secondary Cisco SD-WAN overlay routing for prefixes that are advertised for both data centers. The east data center (TLOC 101.101.101.101) is primary for east sites, and the west data center (TLOC 100.100.100.100) is primary for west sites. Which configuration change achieves this objective?

300-415 Question 64

300-415 Question 64

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 65

How is an event monitored and reported for an individual device in the overlay network at site ID:S4300T6E43F36?

Options:

A.

The device sends event notifications to vManage.

B.

The device sends notifications to vSmart that sends them to vManage.

C.

The device sends a critical alarm of events to vManage.

D.

The device sends a critical alarm to vSmart that sends it to vManage.

Buy Now
Questions 66

300-415 Question 66

Refer to the exhibit. A network administrator is configuring OSPF advanced configuration parameters from a template using the vManager GUI for a branch WAN Edge router to calculate the cost of summary routes to an ASBR. Which action achieves this configuration?

Options:

A.

Enable Originate.

B.

Disable Originate.

C.

Enable RFC 1583 Compatible.

D.

Disable RFC 1583 Compatible.

Buy Now
Questions 67

How is the software managed in Cisco SD-WAN?

Options:

A.

Software images must be uploaded to vManage through HTTP or FTP

B.

Software downgrades are unsupported for vManage

C.

Software images must be transferred through VPN 512 or VPN 0 of vManage

D.

Software upgrade operation in the group must include vManage. vBond, and vSmart.

Buy Now
Questions 68

Which encryption algorithm secures binding exchanges Between Cisco TrustSec SXP peers?

Options:

A.

SEAL

B.

3DES

C.

AES

D.

MD5

Buy Now
Questions 69

Which two algorithms authenticate a user when configuring SNMPv3 monitoring on a WAN Edge router? (Choose two.)

Options:

A.

AES-256

B.

SHA-1

C.

AES-128

D.

MD5

E.

SHA-2

Buy Now
Questions 70

What must an engineer conewef when decoying an SD-WAN on-pfemlses architecture based on ESXi hypervisor?

Options:

A.

Cisco must provision the backup and snapshots platform lor ihe SD-WAN arctoecture

B.

The managed service provider must provision controllars with their appropriate cerHwcatsi

C.

The IT team a required to provision the SO-WAN controllers and Is responsAte lor backups and disaster recovery implementation

D.

The IT team will be given access by Cisco to a vManage for configuration If templates and policies coeigmalim

Buy Now
Questions 71

An engineer provisions a WAN Edge router. Which command should be used from the WAN Edge router to activate it with vManage?

Options:

A.

request vedge-cloud activate serial token

B.

request vedge-cloud activate chassis-number organization

C.

request vedge-cloud activate chassis-number token

D.

request vedge-cloud activate chassis-number serial <:serial>

Buy Now
Questions 72

Which value of the IPsec rekey timer must be set by the engineer for an OMP graceful restart value set for 24 hours?

Options:

A.

6 hours

B.

12 hours

C.

36 hours

D.

48 hours

Buy Now
Questions 73

300-415 Question 73

Refer to the exhibit Which command allows traffic through the IPsec tunnel configured in VPN 0?

Options:

A.

service local

B.

service FW address 1.1.1.1

C.

service netsvc1 vpn 1

D.

service netsvc1 address 1.1.1.1

Buy Now
Questions 74

Which value is verified in the certificates to confirm the identity of the physical WAN Edge device?

Options:

A.

Serial Number

B.

OTP

C.

System-IP

D.

Chassis-ID

Buy Now
Questions 75

300-415 Question 75

Refer to the exhibit. The ge0/0 interface connects to a 30-MB link. A network administrator wants to always have 10 MB available for high priority traffic. When lower-priority traffic busts exceed 20 MB. Traffic should be redirected to the second WAN interface ge0/1. Which set of configurations accomplishes this task?

A)

300-415 Question 75

B)

300-415 Question 75

C)

300-415 Question 75

D)

300-415 Question 75

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 76

How does the Cisco SD-WAN Cloud OnRamp solution rate the performance of a SaaS application from a branch office to the cloud via a given path?

Options:

A.

It computes a quality-of-experience score.

B.

It monitors the packet loss of priority queues.

C.

It counts the number of interface errors.

D.

It measures the delay and jitter of the path.

Buy Now
Questions 77

In an AWS cloud, which feature provision WAN Edge routers automatically in Cisco SD-WAN?

Options:

A.

Cloud app

B.

Cloud OnRamp

C.

vAnalytics

D.

Network Designer

Buy Now
Questions 78

What is the default value for the Multiplier field of the BFD basic configuration in vManage?

Options:

A.

3

B.

4

C.

5

D.

6

Buy Now
Questions 79

An engineer builds a three-node vManage cluster and then realizes that multiple nodes are unnecessary for the size of the company. How should the engineer revert the setup to a single vManage?

Options:

A.

Remove two rode from the three-node vManage duster

B.

Use the cluster conversion utility lo convert to standalone vManage

C.

Restore vManage from the backup VM snapshot

D.

Leave the duller as & and point to one vManage

Buy Now
Questions 80

Drag and drop the steps from the left Into the order on the right to delete a software image for a WAN Edge router starting with Maintenance > Software Upgrade > Device list on vManage.

300-415 Question 80

Options:

Buy Now
Questions 81

A network administrator is configuring an application-aware firewall between inside zones to an outside zone on a WAN edge router using vManage GUI. What kind of Inspection is performed when the ‘’inspect’’ action is used?

Options:

A.

stateful inspection for TCP and UDP

B.

stateful inspection for TCP and stateless inspection of UDP

C.

IPS inspection for TCP and-Layer 4 inspection for UDP

D.

Layer 7 inspection for TCP and Layer 4 inspection for UDP

Buy Now
Questions 82

The SD-WAN network is configured with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use the MPLS TLOC when forwarding Telnet traffic based on a configured SLA class list. Which configured must the engineer use to create a policy to call the SLA class and set the preferred color to MPLS?

A)

300-415 Question 82

B)

300-415 Question 82

C)

300-415 Question 82

D)

300-415 Question 82

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 83

Which Cisco SD-WAN configuration provides the advantages of day-zero deployment and reusable configuration components?

Options:

A.

CLI-based templates

B.

configuration groups

C.

configuration via the vBond controller

D.

configuration through a Cisco Prime server

Buy Now
Questions 84

After deploying Cisco SD-WAN the company realized that by default, all sites built direct IPsec VPN tunnels to each other In their previous topology all spoke sites used the head office as their next hop for the LAN segment that belongs to network 40.0.0.0/16 The company wants to deploy its previous policy, which allows the 40.0.0.0/16 network that originates at the hub to advertise to the spokes. Which configuration meets the requirement'?

A)

300-415 Question 84

B)

300-415 Question 84

C)

300-415 Question 84

D)

300-415 Question 84

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 85

Which component is responsible for creating and maintaining the secure DTLS/TLS connection on the vSmart controller?

Options:

A.

SNMP

B.

vdaemon

C.

NETCONF

D.

OMP

Buy Now
Questions 86

Which vBond system configuration under VPN 0 allows for a routable public IP address even if the DNS name, hostname, or IP address of the vBond orchestrator are omitted?

Options:

A.

local

B.

vbond-only

C.

dns-name

D.

WAN

Buy Now
Questions 87

An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router's local site and then change the DSCP value to DSCP 18 before sending it over to the SD-WAN fabric. What are the two ways to create the required configuration? (Choose two).

300-415 Question 87

300-415 Question 87

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Buy Now
Questions 88

Refer to the exhibit.

300-415 Question 88

The network team must configure branch B WAN Edge device 103 to establish dynamic full-mesh IPsec tunnels between all colors with branches over MPLS and Internet circuits. The branch ts configured with:

300-415 Question 88

300-415 Question 88

Which configuration meets the requirement?

A)

300-415 Question 88

B)

300-415 Question 88

C)

300-415 Question 88

D)

300-415 Question 88

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 89

Which device information is requited on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.

serial and chassis numbers

B.

interface IP address

C.

public DNS entry

D.

system IP address

Buy Now
Questions 90

Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.

300-415 Question 90

Options:

Buy Now
Questions 91

An engineer must automate certificate signing through Cisco. Which vManage configuration achieves this task?

A)

300-415 Question 91

B)

300-415 Question 91

C)

300-415 Question 91

D)

300-415 Question 91

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 92

An engineer is adding a tenant with location ID 399533345 in vManage. What is the maximum number of alphanumeric characters that is accepted in the tenant name filed?

Options:

A.

64

B.

128

C.

256

D.

8

Buy Now
Questions 93

How many vManage NMSs should be installed in each domain to achieve scalability and redundancy?

Options:

A.

two instances

B.

two clusters

C.

three or more in a cluster

D.

two or more in a cluster

Buy Now
Questions 94

Which queue must an engineer configure for control and BFD traffic for convergence on a WAN Edge router?

Options:

A.

queue 0

B.

queue 1

C.

queue 2

D.

queue 7

Buy Now
Questions 95

Refer to the exhibit.

300-415 Question 95

An engineer configured OMP with an overlay-as of 10666. What is the AS-PATH for prefix 104.104.104.104/32 on R100?

Options:

A.

100 10666

B.

100 20 104

C.

100 10666 20 104

D.

100 10666 104

Buy Now
Questions 96

An engineer must use data prefixes to configure centralized data policies using the vManage policy configuration wizard. What is the first step to accomplish this task?

Options:

A.

Create groups of interest

B.

Configure network topology.

C.

Configure traffic rules.

D.

Apply policies to sites and VPNs.

Buy Now
Questions 97

Refer to the exhibit.

300-415 Question 97

What does the BFD value of 8 represent?

Options:

A.

number of BFD sessions

B.

hello timer of BFD session

C.

poll-interval of BFD session.

D.

dead timer of BFD session

Buy Now
Questions 98

Which controller is used for provisioning and configuration in a Cisco SD-WAN solution?

Options:

A.

vBond

B.

Manage

C.

WAN Edge router

D.

vSmart

Buy Now
Questions 99

300-415 Question 99

Refer to the exhibit. Which configuration stops Netconf CLI logging on WAN Edge devices during migration?

300-415 Question 99

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 100

Exhibit.

300-415 Question 100

The SD-WAN network is configured with a default full-mash topology. An engineer wants Barcelona and Paris to communicate to each other through the London site using a control Which control policy configuration accomplishes the task?

A)

300-415 Question 100

B)

300-415 Question 100

C)

300-415 Question 100

D)

300-415 Question 100

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 101

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the master device. What must be configured to get the fastest failover to standby?

Options:

A.

lower timer interval

B.

prefix-list tracking

C.

higher group ID number

D.

OMP tracking

Buy Now
Questions 102

Which component is used to optimize the multicast distribution tree enabled through the multicast network?

Options:

A.

IGMP client

B.

vManage controllers

C.

VPN concentrator

D.

OMP replicator

Buy Now
Questions 103

An engineer must configure local redundancy on a site. Which configuration accomplish this task?

Options:

A.

vpn 0interface interface-name

B.

tloc extension interlace nametloc extension interface interface name

C.

vpn 0tloc extension interface

D.

interface-flameinterface interface-name tloc-extension

Buy Now
Questions 104

A company is using Catalyst SD-WAN Manager as its root certificate authority server and must generate a root certificate using the vShell (Linux) built into the CLI of Catalyst SD-WAN Manager. Which command must be issued to generate the root certificate?

Options:

A.

openssl req -x509 -new-nodes -key XYZ.pem -sha256 -days 365 \subj "/C=US/ST=DC/L=DC/O=Cisco/CN=device.lab"-out ABC.key

B.

openssl genrsa -out ROOTCA.pem 2048

C.

openssl req -x509 -new-nodes -key XYZ.key -sha256 -days 365 Isubj "/C-US/ST-DC/L-DC/O-Cisco/CN-device.lab" 1-out ABC.pem

D.

openssl genrsa -out ROOTCA.key 2048

Buy Now
Questions 105

300-415 Question 105

Refer to the exhibit. The Cisco SD-VYAN is deployed using the default topology. The engineer v/ants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Sen/ice VPN ID is 1?

A)

300-415 Question 105

B)

300-415 Question 105

C)

300-415 Question 105

D)

300-415 Question 105

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 106

Which policy configures an application-aware routing policy under Configuration > Policies?

Options:

A.

Localized policy

B.

Centralized policy

C.

Data policy

D.

Control policy

Buy Now
Questions 107

An engineering team must prepare a traffic engineering policy where an MPLS circuit is preferred for traffic coming from the Admin VLAN Internet should be used as a backup only. Which configuration fulfill this requirement?

A)

300-415 Question 107

B)

300-415 Question 107

C)

300-415 Question 107

D)

300-415 Question 107

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 108

300-415 Question 108

Refer to the exhibit. An administrator is configuring a policy in addition to an existing hub-and-spoke policy for two sites that should directly communicate with each other. How is this policy configured?

Options:

A.

hub-and-spoke

B.

mesh

C.

import existing topology

D.

custom control (route and TLOC)

Buy Now
Questions 109

Refer to the exhibit.

300-415 Question 109

The SD-WAN network is configured with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use MPLS TLOC as the preferred TLOC when communicating with Rome site. Which configuration must the engineer use to create a list to select MPLS color toward the Rome TLOC?

A)

300-415 Question 109

B)

300-415 Question 109

C)

300-415 Question 109

D)

300-415 Question 109

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 110

Drag and drop the functions from the left onto the correct templates on the right.

300-415 Question 110

Options:

Buy Now
Questions 111

How is lhe software managed in Cisco SD-WAN?

Options:

A.

Software upgrade operation in the group must include vManage. vBond. and vSmart.

B.

Software downgrades are unsupported for vManage

C.

Software images must be uploaded to vManage through HTTP or FTP.

D.

Software images must be transferred through VPN 512 or VPN 0 of vManage.

Buy Now
Questions 112

Drag and drop the Cisco SD-WAN components from the left onto their functions on the right.

300-415 Question 112

Options:

Buy Now
Questions 113

An engineer creates this data policy for DIA for VPN 10:

300-415 Question 113

Which policy sequence enables DIA for external networks?

300-415 Question 113

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 114

An application team is getting ready to deploy a new business-critical application to the network. To protect the traffic, the network team must add another queue to the QoS map and then deploy the map to fabric Which configuration slop must be completed prior to adding the queue to the QoS map and applying If

Options:

A.

The relationship between die new QoS class and the hardware queue must be configured from the 'lists' page of the Local Policy section of vManage. The QoS map is then applied to the WAN interface

B.

The relationship between The new QoS class and the hardware queue must be configured from the 'lists' page of the Local Policy section of vManage. The QoS map is then applied to the service-side interface.

C.

The relationship between the new QoS class and the hardware queue must be configured from the "lisla" page of the Centralized Policy section of vManage. The QoS map is then applied to the WAN interface.

D.

The relationship between the new QoS class and the hardware queue must be configured from the "lists" page of the Centralized Policy section of vManage. The QoS map is then applied to the service-side interface.

Buy Now
Questions 115

An engineer is modifying an existing data policy for VPN 115 to meet these additional requirements:

    When browsing government websites, the traffic must use direct internet access.

    The source address of the traffic leaving the site toward the government websites must be set to an IP range associated with the country itself, a particular TLOC.

The policy configuration is as follows:

300-415 Question 115

Which policy sequence meets the requirements without interfering with other destinations?

Options:

A.

sequence 30

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

B.

sequence 25

match

destination-data-prefix-list GOVERNMENT-WEBSITES

action accept

nat use-vpn 0

C.

sequence 15

match

source-data-prefix-list GOVERNMENT-WEBSITES

action accept

set

local-tloc-list

color private1

D.

sequence 15

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

Buy Now
Questions 116

A Cisco SD-WAN customer has a requirement to calculate the SHA value for files as they pass through the device to see the returned disposition and determine if the file is good, unknown or malicious. The customer also wants to perform real-time traffic analysis and generate alerts when threats are detected Which two Cisco SD-WAN solutions meet the requirements? (Choose two.)

Options:

A.

Cisco Trust Anchor Module

B.

Cisco Threat Grid

C.

Cisco Snort IPS

D.

Cisco AMP

E.

Cisco Secure Endpoint

Buy Now
Questions 117

300-415 Question 117

Refer to the exhibit. An engineer configures a hub-and-spoke SD-WAN topology with the requirement that traffic from router A branch to router B branch is guaranteed to flow through the network hub, router C. Which configuration meets the requirement for router A?

300-415 Question 117

300-415 Question 117

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 118

A company deploys a Cisco SD-WAN solution but has an unstable Internet connection. When the link to vSmart comes back up, the WAN Edge router routing table is not refreshed, and some traffic to the destination network is dropped. The headquarters is the hub site, and it continuously adds new sites to the SD-WAN network. An engineer must configure route refresh between WAN Edge and vSmart within 2 minutes. Which configuration meets this requirement?

300-415 Question 118

Options:

A.

Option A

B.

B

C.

Option B

D.
E.

Option C

F.

Option D

Buy Now
Questions 119

Which command disables the logging of syslog messages to the local disk?

Options:

A.

no system logging disk enable

B.

no system logging disk local

C.

system logging disk disable

D.

system logging server remote

Buy Now
Questions 120

In Cisco SD-WAN, what protocol is used for control connections between SD-WAN devices?

Options:

A.

DTLS

B.

OMP

C.

BGP

D.

OSPF

Buy Now
Questions 121

Which TLOC color is used for site-to-site communication in a Google Cloud integration with Cisco SD-WAN?

Options:

A.

Private1

B.

private2

C.

private3

D.

private4

Buy Now
Questions 122

300-415 Question 122

Refer to the exhibit Which NAT types must the engineer configure for the vEdge router to bring up the data plane tunnels?

Options:

A.

Enable Full Cone NAT on the vEdge interface

B.

Use public color on the TLOC

C.

Use private color on the TLOC

D.

Enable Symmetric MAT on the vEdge interface

Buy Now
Questions 123

How is TLOC defined?

Options:

A.

It is represented by a unique identifier to specify a site in as SD-WAN architecture.

B.

It specifies a Cisco SD-WAN overlay in a multitenant vSMART deployment.

C.

It is a unique collection of GRE or iPsec encapsulation, link color, and system IP address.

D.

It is represented by group of QoS policies applied to a WAN Edge router.

Buy Now
Questions 124

Which logs verify when a device was upgraded?

Options:

A.

Audit

B.

Email

C.

ACL

D.

SNMP

Buy Now
Questions 125

If Smart Account Sync is not used, which Cisco SD-WAN component is used to upload an authorized serial number file?

Options:

A.

WAN Edge

B.

vManage

C.

vSmart

D.

vBond

Buy Now
Questions 126

Which policy tracks path characteristics such as loss, latency, and jitter in vManage?

Options:

A.

VPN

B.

control

C.

app-route

D.

data

Buy Now
Questions 127

Which two platforms for the Cisco SD-WAN architecture are deployable in a hypervisor on-premises or in IAAS Cloud? (Choose two.)

Options:

A.

CSR 1000v

B.

vEdge 100c

C.

vEdge Cloud

D.

vEdge 2000

E.

ISR 4431

Buy Now
Questions 128

The branch users of an organization must be prevented from accessing malicious destinations, and the local files on users' systems must be protected from malware. Which two Cisco products must the organization deploy? (Choose two.)

Options:

A.

Cisco Stealthwatch

B.

Cisco Umbrella

C.

Cisco AMP

D.

Cisco Cloudlock

E.

Cisco SecureX

Buy Now
Questions 129

300-415 Question 129

Refer to the exhibit. Which configuration ensures that OSPP routes learned from Site2 are reachable at Stein and vice-versa?

Options:

A.
B.
C.
Buy Now
Questions 130

Which two REST API functions are performed for Cisco devices in an overlay network? (Choose two)

Options:

A.

distributing a Snort image among devices

B.

attaching a device configuration template

C.

managing connections for smart licensing

D.

monitoring device certificates

E.

querying a device and aggregating statistics

Buy Now
Questions 131

An enterprise has several sites with multiple VPNs that are isolated from each other A new requirement came where users in VPN 73 must be able to talk to users in VPN 50 Which configuration meets this requirement?

300-415 Question 131

300-415 Question 131

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 132

WAN Edge routers are configured manually to use UDP port offset to use nondefault offset values when IPsec tunnels are created. What is the offse range?

Options:

A.

1-19

B.

0-18

C.

0-19

D.

1-18

Buy Now
Questions 133

An engineer must configure two branch WAN Edge devices where an Internet connection is available and the controllers are in the headquarters. The requirement is to have IPsec VPN tunnels established between the same colors. Which configuration meets the requirement on both WAN Edge devices?

300-415 Question 133

300-415 Question 133

300-415 Question 133

300-415 Question 133

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Exam Code: 300-415
Exam Name: Implementing Cisco SD-WAN Solutions (300-415 ENSDWI)
Last Update: Apr 5, 2026
Questions: 446

PDF + Testing Engine

$65.27  $186.49

Testing Engine

$52.32  $149.49
buy now 300-415 testing engine

PDF (Q&A)

$48.12  $137.49
buy now 300-415 pdf