Big Cyber Monday Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

300-415 Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Questions 4

What are the two functions of vSmart? (Choose two)

Options:

A.

It orchestrates connectivity between WAN Edge routers using policies to create network topology

B.

It ensures that valid WAN Edge routers can build the control pane connectivity

C.

It uses TLOCs to uniquely identify the circuit interface to control plane and data plane information

D.

It validates that the WAN Edge trying to join the overlay is authorized to join.

E.

It builds control plane connections with WAN Edge routers using ILS or UILS

Buy Now
Questions 5

Which routing protocol has the highest default administrative distance?

Options:

A.

OMP

B.

external EIGRP

C.

IS-IS

D.

IBGP

Buy Now
Questions 6

An engineer is configuring a data policy for packets that must be captured through the policy. Which command accomplishes this task?

Options:

A.

policy > data-policy > vpn-list > sequence > default-action > drop

B.

policy > data-policy > vpn-list > sequence > action

C.

policy > data-policy > vpn-list > sequence > default-action > accept

D.

policy > data-policy > vpn-list > sequence > match

Buy Now
Questions 7

What is the minimum Red Hat Enterprise Linux operating system requirement for a Cisco SD-WAN controller deployment via KVM?

Options:

A.

RHEL7.5

B.

RHEL 6.5

C.

RHEL4.4

D.

RHEL 6.7

Buy Now
Questions 8

Which feature allows reachability to an organization’s internally hosted application for an active DNS security policy on a device?

Options:

A.

local domain bypass

B.

DHCP option 6

C.

DNSCrypt configurator

D.

data pokey with redirect

Buy Now
Questions 9

Which Cisco SD-WAN feature propagates packets with SGTs through the network?

Options:

A.

TrustSec Inline Tagging

B.

SGT Enforcement

C.

QoE

D.

SXP

Buy Now
Questions 10

Which feature template configures OMP?

A)

300-415 Question 10

B)

300-415 Question 10

C)

300-415 Question 10

D)

300-415 Question 10

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 11

What is the threshold to generate a warning alert about CPU or memory usage on a WAN Edge router?

Options:

A.

70 to 85 percent

B.

70 to 90 percent

C.

75 to 85 percent

D.

75 to 90 percent

Buy Now
Questions 12

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop malicious attachments before they reach users and get executed. Which Cisco SD-WAN solution meets the requirements?

Options:

A.

Cisco Trust Anchor module

B.

URL filtering and Umbrella DNS security

C.

Cisco AMP and Threat Grid

D.

Snort IPS

Buy Now
Questions 13

Drag and drop the steps from the left into the order on the right to delete a software image for a WAN Edge router starting with Maintenance > Software Upgrade > Device list on vManage.

300-415 Question 13

Options:

Buy Now
Questions 14

Which compression algorithm does DRE use in a Cisco SD-WAN environment?

Options:

A.

run-length encoding

B.

Lempel-Ziv-Welch encoding

C.

Ziv Huffman encoding

D.

Huffman encoding

Buy Now
Questions 15

What prohibits deleting a VNF image from the software repository?

Options:

A.

if the image is stored by vManage

B.

if the image is referenced by a service chain

C.

if the image is uploaded by a WAN Edge device

D.

if the image is included in a configured policy

Buy Now
Questions 16

An administrator needs to configure SD-WAN to divert traffic from the company's private network to an ISP network. What action should be taken to accomplish this goal?

Options:

A.

configure the control policy

B.

configure the data policy

C.

configure the data security policy

D.

configure the application aware policy

Buy Now
Questions 17

Refer to the exhibit.

300-415 Question 17

An engineer is configuring service chaining. Which set of configurations is required for all traffic from Site ID 1 going toward Site ID 2 to get filtered through the firewall on the hub site?

A)

300-415 Question 17

B)

300-415 Question 17

C)

300-415 Question 17

D)

300-415 Question 17

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 18

A network administrator is creating an OMP feature template from the vManage GUI to be applied to WAN edge routers. Which configuration attribute will avoid the redistribution of the routes back into the OMP from the LAN side?

Options:

A.

configure "Number of Paths Advertised per Prefix"

B.

configure "Overlay AS Number"

C.

configure "Send Backup Paths"

D.

configure "ECMP limit"

Buy Now
Questions 19

Which Cisco router provides a distributed multicore architecture optimized for SD-WAN branch support?

Options:

A.

Cisco 1000 ISR series

B.

Cisco 2900 ISR series

C.

Cisco Catalyst 3850 series

D.

Cisco 3900 ISR series

Buy Now
Questions 20

Where on vManage does an engineer find the details of control node failure?

Options:

A.

Alarms

B.

Events

C.

Audit log

D.

Network

Buy Now
Questions 21

Which statement describes the requirement of integrating a secure internet gateway (SIG) with a Cisco SD-WAN Edge device?

Options:

A.

Attached to SIG tunnels, trackers monitor the respective SIG endpoints.

B.

Credentials for a smart account are required.

C.

A Cisco umbrella organization ID is needed to establish the SIG.

D.

Based on routing or policy, all customer internet traffic must be forwarded to the SIG.

Buy Now
Questions 22

What is an attribute of TLOC’?

Options:

A.

encryption

B.

local preference

C.

tag

D.

service

Buy Now
Questions 23

An engineer must apply the configuration for certificate installation to vBond Orchestrator and vSmart Controller. Which configuration accomplishes this task?

300-415 Question 23

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 24

Refer to the exhibit.

300-415 Question 24

The tunnel interface configuration on both WAN Edge routers is:

300-415 Question 24

Which configuration for WAN Edge routers will connect to the Internet?

300-415 Question 24

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 25

A network is configured with CoPP to protect the CORE router route processor for stability and DDoS protection. As a company policy, a class named class-default is preconfigured and must not be modified or deleted. Troubleshoot CoPP to resolve the issues introduced during the maintenance window to ensure that:

300-415 Question 25

300-415 Question 25

WAN

300-415 Question 25

300-415 Question 25

300-415 Question 25

CORE

300-415 Question 25

300-415 Question 25

300-415 Question 25

300-415 Question 25

MGMT

300-415 Question 25

300-415 Question 25

Options:

Buy Now
Questions 26

300-415 Question 26

Refer to the exhibit. An administrator is configuring a policy in addition to an existing hub-and-spoke policy for two sites that should directly communicate with each other. How is this policy configured?

Options:

A.

hub-and-spoke

B.

mesh

C.

import existing topology

D.

custom control (route and TLOC)

Buy Now
Questions 27

300-415 Question 27

Refer to the exhibit. The ge0/0 interface connects to a 30-MB link. A network administrator wants to always have 10 MB available for high priority traffic. When lower-priority traffic busts exceed 20 MB. Traffic should be redirected to the second WAN interface ge0/1. Which set of configurations accomplishes this task?

A)

300-415 Question 27

B)

300-415 Question 27

C)

300-415 Question 27

D)

300-415 Question 27

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 28

300-415 Question 28

Refer to the exhibit. The Cisco SD-WAN is deployed using the default topology. The engineer wants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Service VPN ID is 1?

Options:

A.

300-415 Question 28 Option 1

B.

28

C.

28

D.

28

Buy Now
Questions 29

300-415 Question 29

Refer to the exhibit. An engineer configures a hub-and-spoke SD-WAN topology with the requirement that traffic from router A branch to router B branch is guaranteed to flow through the network hub, router C. Which configuration meets the requirement for router A?

300-415 Question 29

300-415 Question 29

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 30

How is TLOC defined?

Options:

A.

It is represented by a unique identifier to specify a site in as SD-WAN architecture.

B.

It specifies a Cisco SD-WAN overlay in a multitenant vSMART deployment.

C.

It is a unique collection of GRE or iPsec encapsulation, link color, and system IP address.

D.

It is represented by group of QoS policies applied to a WAN Edge router.

Buy Now
Questions 31

300-415 Question 31

300-415 Question 31

Refer to the exhibit vManage and vBond have an issue establishing a connection with each other Which action resolves the issue?

Options:

A.

Reconfigure the system IPs to belong to the same subnet

B.

Change the organization name on both controllers to match vipteta.com.

C.

Remove the encapsulation ipsec command under the tunnel interface of vBond

D.

Configure the encapsulation ipsec command under the tunnel interface on vManage

Buy Now
Questions 32

300-415 Question 32

300-415 Question 32

300-415 Question 32

Refer to the exhibit A small company was acquired by a large organization As a result, the new organization decided to update information on their Enterprise RootCA and generated a new certificate using openssl Which configuration updates the new certificate and issues an alert in vManage Monitor | Events Dashboard?

300-415 Question 32

300-415 Question 32

300-415 Question 32

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 33

What happens if the intelligent proxy is unreachable in the Cisco SD-WAN network?

Options:

A.

The grey-listed domains are unresolved

B.

The Cisco Umbrella Connector locally resolves the DNS request

C.

The block-listed domains are unresolved

D.

The Cisco Umbrella Connector temporarily redirects HTTPS traffic

Buy Now
Questions 34

In which device state does the WAN edge router create control connections, but data tunnels are not created?

Options:

A.

valid

B.

backup

C.

active

D.

staging

Buy Now
Questions 35

300-415 Question 35

Refer to the exhibit. Which configuration stops Netconf CLI logging on WAN Edge devices during migration?

300-415 Question 35

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 36

What is the function of colocation in Cloud OnRamp SaaS?

Options:

A.

Cloud OnRamp incorporates regional colocation facilities by choosing between cloud access points at the remote site and regional cloud access points at the colocation facilities.

B.

The Cloud OnRamp for colocation solution restricts the creation of different VNF service chains orchestrated in Cisco vManage and deployed on a cluster in a colocation facility.

C.

In Cloud OnRamp. colocation supports the capability of virtualizing access-only locations and using colocation centers that require the customer to extend to the cloud.

D.

With colocation facility in Cloud OnRamp. the customer faces challenges to virtualize the security and optimization infrastructure that influence traffic through network elements.

Buy Now
Questions 37

What is a requirement for deployment of on-premises vBond controllers through the Cisco Plug and Play Connect process?

Options:

A.

a DNS name that identifies vBond

B.

a defined controller profile

C.

Internet connectivity from vManage

D.

a CSV The that contains ail controllers

Buy Now
Questions 38

Which two algorithms authenticate a user when configuring SNMPv3 monitoring on a WAN Edge router? (Choose two.)

Options:

A.

AES-256

B.

SHA-1

C.

AES-128

D.

MD5

E.

SHA-2

Buy Now
Questions 39

Which table is used by the vSmart controller to maintain service routes of the WAN Edge routers in the hub and local branches?

Options:

A.

RIB

B.

FIB

C.

OMP

D.

TLOC

Buy Now
Questions 40

300-415 Question 40

Refer to the exhibit Which configuration must the engineer use to form underlay connectivity for the Cisco SD-WAN network?

A)

300-415 Question 40

B)

300-415 Question 40

C)

300-415 Question 40

D)

300-415 Question 40

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 41

An engineer must apply the configuration for certificate installation to vBond Orchestrator and vSmart Controller. Which configuration accomplishes this task?

300-415 Question 41

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 42

Which two prerequisites must be met before the Cloud onRamp for laaS is initiated on vManage to expand to the AWS cloud? (Choose two)

Options:

A.

Attach the *AmazonCreateVPC* and "Amazon Provision EC2" permission policy to the IAM account

B.

Subscribe to the SD-WAN Edge router AMI in the AWS account

C.

Attach an OSPF feature template to the AWS cloud Edge router template

D.

Attach a device template to the cloud WAN Edge router to be deployed in the AWS

E.

Preprovision the transit VPC in the AWS region

Buy Now
Questions 43

Which percentage for total memory or total CPU usage for a device is classified as normal in the WAN Edge Health pane?

Options:

A.

more than 80 percent usage

B.

less than 70 percent usage

C.

between 70 to 90 percent usage

D.

more than 90 percent usage

Buy Now
Questions 44

Which configuration allows users to reach YouTube from a local Internet breakout?

A)

300-415 Question 44

B)

300-415 Question 44

C)

300-415 Question 44

D)

300-415 Question 44

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 45

Which set of elements are verified by the controller to confirm the identity of edge devices?

Options:

A.

certificates, organization name and serial number of the device

B.

organization name serial number and system IP of the device

C.

certificates, organization name, and vBond domain

D.

certificates, system IP, and vBond domain

Buy Now
Questions 46

Which destination UDP port is used by WAN Edge router to make a DTLS connection with vBond Orchestrator?

Options:

A.

12343

B.

12345

C.

12346

D.

12347

Buy Now
Questions 47

The SD-WAN network is configured ­­­with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use the MPLS TLOC when forwarding Telnet traffic based on a configured SLA class list. Which configured must the engineer use to create a policy to call the SLA class and set the preferred color to MPLS?

A)

300-415 Question 47

B)

300-415 Question 47

C)

300-415 Question 47

D)

300-415 Question 47

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 48

Which vBond system configuration under VPN 0 allows for a routable public IP address even if the DNS name, hostname, or IP address of the vBond orchestrator are omitted?

Options:

A.

local

B.

vbond-only

C.

dns-name

D.

WAN

Buy Now
Questions 49

What are two benefits of installing Cisco SD-WAN controllers on cloud-hosted services? (Choose two.)

Options:

A.

utilizes well-known cloud services such as Azure. AWS. and GCP

B.

accelerates Cisco SD-WAN deployment

C.

allows integration of the WAN Edge devices In the cloud

D.

installs the controllers in two cloud regions in a primary and backup setup

E.

automatically Implements zone-based firewalling on the controllers

Buy Now
Questions 50

The branch users of an organization must be prevented from accessing malicious destinations, and the local files on users' systems must be protected from malware. Which two Cisco products must the organization deploy? (Choose two.)

Options:

A.

Cisco Stealthwatch

B.

Cisco Umbrella

C.

Cisco AMP

D.

Cisco Cloudlock

E.

Cisco SecureX

Buy Now
Questions 51

An engineer must create a QoS policy by creating a class map and assigning it to the LLQ queue on a WAN Edge router Which configuration accomplishes the task?

A)

300-415 Question 51

B)

300-415 Question 51

C)

300-415 Question 51

D)

300-415 Question 51

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 52

Refer to the exhibit.

300-415 Question 52

An enterprise has hub and spoke topology where it has several VPNs. An engineer must allow users in VPN91 to reach users in VPN92 and VPN10 to reach VPN91 and VPN92. Which configuration meets these requirements?

300-415 Question 52

300-415 Question 52

300-415 Question 52

300-415 Question 52

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 53

Which SD-WAN component detects path performance information in the organization to report the issue to the service provider at site ID:S4288T5E44F04?

Options:

A.

vAnalytics

B.

vManage NMS

C.

vBond Orchestrator

D.

Cisco DNA

Buy Now
Questions 54

What is the ZTP workflow for Cisco IOS XE-based devices?

300-415 Question 54

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 55

An engineer must advertise OSPF-learned routes and modify the update interval for route filtering by TLOC color to 300 on an SD-WAN device. Which configuration accomplishes this

task?

300-415 Question 55

300-415 Question 55

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 56

Which TCP Optimization feature is used by WAN Edge to prevent unnecessary retransmissions and large initial TCP window sizes to maximize throughput and achieve a better quality?

Options:

A.

SEQ

B.

SYN

C.

RTT

D.

SACK

Buy Now
Questions 57

An engineer wants to change the configuration of the certificate authorization mode from manual to automated. Which GUI selection will accomplish this?

Options:

A.

Maintenance > Security

B.

Configuration > Certificates

C.

Administration > Settings

D.

Tools > Operational Commands

Buy Now
Questions 58

An enterprise needs DIA on some of its branches with a common location ID: A041:B70C: D78E::18 Which WAN Edge configuration meets the requirement?

A)

300-415 Question 58

B)

300-415 Question 58

C)

300-415 Question 58

D)

300-415 Question 58

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 59

Which controller is used for provisioning and configuration in a Cisco SD-WAN solution?

Options:

A.

vBond

B.

Manage

C.

WAN Edge router

D.

vSmart

Buy Now
Questions 60

A network administrator is configuring a tunnel interface on a branch Cisco IOS XE router to run TLOC extensions. Which configuration will extend a TLOC over a GRE tunnel to another router in the branch?

300-415 Question 60

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 61

What do receivers request to join multicast streams in a Cisco SO-WAN network?

Options:

A.

IGMP membership reports directly with a multicast router.

B.

Multicast service routes with the vSmart controller

C.

IGMP membership reports directly with the vBond orchestrator.

D.

PIM messages with the nearest neighboring multicast router.

Buy Now
Questions 62

How must the application-aware enterprise firewall policies be applied within the same WAN Edge router?

Options:

A.

within and between zones

B.

between two VPN tunnels

C.

within zone pair

D.

between two VRFs

Buy Now
Questions 63

What are two attributes of vRoute? (Choose two)

Options:

A.

originator

B.

service

C.

encapsulation

D.

carrier

E.

domain ID

Buy Now
Questions 64

What is a requirement for a WAN Edge to reach vManage, vBond, and vSmart controllers in a data center?

Options:

A.

IGP

B.

QoS

C.

TLS

D.

OMP

Buy Now
Questions 65

Drag and drop the security terminologies from the left onto the PCI-compliant network features and devices on the right.

300-415 Question 65

Options:

Buy Now
Questions 66

Refer to the exhibit.

300-415 Question 66

An engineer is troubleshooting a control connection Issue. What does "connect" mean in this how control connections output?

Options:

A.

Control connection is down

B.

Control connection is connected

C.

Control connection attempt is in progress

D.

Control connection is up

Buy Now
Questions 67

A network administrator is bringing up one WAN Edge for branch connectivity. Which types of tunnels form when the WAN edge router connects to the SD-WAN fabric?

Options:

A.

DTLS or TLS tunnel with vBond controller and IPsec tunnel with vManage controller.

B.

DTLS or TLS tunnel with vBond controller and IPsec tunnel with other WAN Edge routers.

C.

DTLS or TLS tunnel with vSmart controller and IPsec tunnel with other Edge routers.

D.

DTLS or TLS tunnel with vSmart controller and IPsec tunnel with vBond controller.

Buy Now
Questions 68

Which component of the Cisco SD-WAN architecture oversees the control plane of overlay network to establish, adjust, and maintain the connections between the WAN Edge devices that form the Cisco SD-WAN fabric?

Options:

A.

APIC-EM

B.

vManage

C.

vSmart

D.

vBond

Buy Now
Questions 69

When the VPN membership policy is being controlled at the vSmart controller, which policy disallows VPN 1 at sites 20 and 30?

A)

300-415 Question 69

B)

300-415 Question 69

C)

300-415 Question 69

D)

300-415 Question 69

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 70

Which two different states of a WAN Edge certificate are shown on vManage? (Choose two.)

Options:

A.

inactive

B.

active

C.

staging

D.

invalid

E.

provisioned

Buy Now
Questions 71

Which secure tunnel type should be used to connect one WAN Edge router to other WAN Edge routers?

Options:

A.

TLS

B.

DTLS

C.

SSL VPN

D.

IPsec

Buy Now
Questions 72

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.

Cloud Services Platform

B.

VNF Service Chaning

C.

Cloud onRamp for Colocation

D.

Cloud onRamp for laaS

Buy Now
Questions 73

Which protocol is used to propagate multicast join requests over the Cisco SD-WAN fabric?

Options:

A.

ARP

B.

Auto-RP

C.

OMP

D.

IGMP

Buy Now
Questions 74

What is the main purpose of using TLOC extensions in WAN Edge router configuration?

Options:

A.

creates hardware-level transport redundancy at the local site

B.

creates an IPsec tunnel from WAN Edge to vBond Orchestrator

C.

transports control traffic to a redundant vSmart Controller

D.

transports control traffic w remote-site WAN Edge routers

Buy Now
Questions 75

Which device information is requited on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.

serial and chassis numbers

B.

interface IP address

C.

public DNS entry

D.

system IP address

Buy Now
Questions 76

Which configuration component is used in a firewall security policy?

Options:

A.

numbered sequences of match-action pairs

B.

application match parameters

C.

URL filtering policy

D.

intrusion prevention policy

Buy Now
Questions 77

What two functions describe the TCP optimization tool used in the Cisco SD-WAN? (Choose two.)

Options:

A.

It uses TCP acknowledgment (ACK).

B.

It is used to take care of high packet loss for control traffic.

C.

It terminates TCP connections locally at the WAN edge.

D.

It uses TCP selective acknowledgment (SACK).

E.

It terminates TCP connections at the remote WAN edge.

Buy Now
Questions 78

An engineer wants to track tunnel characteristics within an SLA-based policy for convergence. Which policy configuration will achieve this goal?

Options:

A.

App-route policy

B.

VPN membership policy

C.

Control policy

D.

Data policy

Buy Now
Questions 79

When VPNs are grouped to create destination zone in Zone-Based Firewall, how many zones can a single VPN be part of?

Options:

A.

two

B.

four

C.

one

D.

three

Buy Now
Questions 80

What are the two requirements for plug-and-play provisioning on Cisco IOS XE SD-WAN devices? (Choose two.)

Options:

A.

The gateway router for the WAN Edge device must be able to reach devicehelper.cisco.com.

B.

The gateway router for the WAN Edge device must be able to reach public DNS servers.

C.

The gateway router for the WAN Edge device must be able to reach ztp.viptela.com.

D.

Devices at branch offices must be able to reach the Cisco SD-WAN vSmart controller at the headquarters site.

E.

The WAN Edge device must have a valid certificate.

Buy Now
Questions 81

Refer to the exhibit.

300-415 Question 81

Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)

Options:

A.

Generate a CSR manually within vManage server

B.

Generate a CSR manually on the WAN Edge

C.

Request a certificate manually from the Enterprise CA server

D.

Install the certificate received from the CA server manually on the WAN Edge

E.

Install the certificate received from the CA server manually on the vManage

Buy Now
Questions 82

Which configuration step is taken on vManage after WAN Edge list is uploaded?

Options:

A.

Send the list to controllers

B.

Enable the ZTP process

C.

Verify the device certificate

D.

Set the device as valid

Buy Now
Questions 83

Drag and drop the devices from the left onto the correct functions on the right.

300-415 Question 83

Options:

Buy Now
Questions 84

An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router's local site and then change the DSCP value to DSCP 18 before sending it over to the SD-WAN fabric. What are the two ways to create the required configuration? (Choose two).

300-415 Question 84

300-415 Question 84

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Buy Now
Questions 85

Which two platforms for the Cisco SD-WAN architecture are deployable in a hypervisor on-premises or in IAAS Cloud? (Choose two.)

Options:

A.

CSR 1000v

B.

vEdge 100c

C.

vEdge Cloud

D.

vEdge 2000

E.

ISR 4431

Buy Now
Questions 86

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

300-415 Question 86

300-415 Question 86

300-415 Question 86

300-415 Question 86

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 87

Which service VPN must be reachable from all WAN Edge devices and the controllers?

Options:

A.

VPN0

B.

VPN10

C.

VPN215

D.

VPN512

Buy Now
Questions 88

Which port is used for vBond under controller certificates if no alternate port is configured?

Options:

A.

12345

B.

12347

C.

12346

D.

12344

Buy Now
Questions 89

Drag and drop the definitions from the left to the configuration on the right.

300-415 Question 89

Options:

Buy Now
Questions 90

An engineer must deploy a QoS policy with these requirements:

• policy name: App-police

• police rate: 1000000

• burst: 1000000

• exceed: drop

Which configuration meets the requirements?

300-415 Question 90

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 91

Which platform cannot provide IPS and URL filtering capabilities?

Options:

A.

Cisco CSR 1000V

B.

Cisco ISR 1000

C.

Cisco Catalyst 8300

D.

Cisco ISR 4000

Buy Now
Questions 92

Which action is performed during the onboarding process when a WAN Edge router is connected to ZTP server ztp.viptela com?

Options:

A.

The router is connected to WAN Edge Cloud Center

B.

The router is synced with vSmart Controller via an IPsec tunnel

C.

The router receives its vBond Orchestrator information

D.

The router is connected 10 vSmart Controller via a DTLSTLS tunnel

Buy Now
Questions 93

300-415 Question 93

Refer to the exhibit. vManage logs are available for the past few months. A device name change deployed mistakenly at a critical site. How is the device name change tracked by operation and design teams?

A)

300-415 Question 93

B)

300-415 Question 93

C)

300-415 Question 93

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 94

A network administrator is tasked to make sure that an OMP peer session is closed after missing three consecutive keepalive messages in 3 minutes. Additionally, route updates must be sent every minute. If a WAN Edge router becomes unavailable, the peer must use last known information to forward packets for 12 hours. Which set of configuration commands accomplishes this task?

300-415 Question 94

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 95

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the master device. What must be configured to get the fastest failover to standby?

Options:

A.

lower timer interval

B.

prefix-list tracking

C.

higher group ID number

D.

OMP tracking

Buy Now
Questions 96

Refer to the exhibit.

300-415 Question 96

The network design team has advised to use private IP addresses and private colors over the SP circuit for the data plane connections. The Public IP should be used for control connections. Which configuration should be applied at SiteA to achieve this task?

300-415 Question 96

300-415 Question 96

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 97

A company must avoid downtime at the remote sites and data plane to continue forwarding traffic between WAN Edge devices if the branch router loses connectivity to its OMP peers Which configuration meets the requirement?

A)

300-415 Question 97

B)

300-415 Question 97

C)

300-415 Question 97

D)

300-415 Question 97

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 98

300-415 Question 98

Refer to the exhibit An engineer is configuring a QoS policy to shape traffic for VLAN 100 on a subinterface Which policy configuration accomplishes the task?

A)

300-415 Question 98

B)

300-415 Question 98

C)

300-415 Question 98

D)

300-415 Question 98

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 99

Which two hardware platforms support Cisco IOS XE SD-WAN images'' (Choose two)

Options:

A.

ASR1000 series

B.

ISR9300 series

C.

vEdge-1000 series

D.

ASR9000 series

E.

ISR4000 series

Buy Now
Questions 100

Which device information is required on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.

interface IP address

B.

system IP address

C.

public DNS entry

D.

serial and chassis numbers

Buy Now
Questions 101

300-415 Question 101

Refer to the exhibit, Which configuration routes Site 2 through the firewall in Site 1?

300-415 Question 101

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 102

Which protocol is configured on tunnels by default to detect loss, latency, jitter, and path failures in Cisco SD-WAN?

Options:

A.

TLS

B.

BFD

C.

OMP

D.

BGP

Buy Now
Questions 103

An engineer is modifying an existing data policy for VPN 115 to meet these additional requirements:

    When browsing government websites, the traffic must use direct internet access.

    The source address of the traffic leaving the site toward the government websites must be set to an IP range associated with the country itself, a particular TLOC.

The policy configuration is as follows:

300-415 Question 103

Which policy sequence meets the requirements without interfering with other destinations?

Options:

A.

sequence 30

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

B.

sequence 25

match

destination-data-prefix-list GOVERNMENT-WEBSITES

action accept

nat use-vpn 0

C.

sequence 15

match

source-data-prefix-list GOVERNMENT-WEBSITES

action accept

set

local-tloc-list

color private1

D.

sequence 15

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

Buy Now
Questions 104

What are the two impacts of losing vManage connectivity to fabric in the Cisco SD-WAN network? (Choose two)

Options:

A.

Policy changes propagation stops

B.

Statistics collection stops

C.

BFD peering between WAN Edge devices are unestablished

D.

Creation of templates is impossible

E.

IPsec tunnels tear down for WAN Edge devices.

Buy Now
Questions 105

How many vCPUs and how much RAM are recommended to run the vSmart controller on the KVM server for 251 to 1000 devices in software version 20.4.x?

Options:

A.

4vCPUs. 16 GB

B.

4 vCPUs. 8 GB

C.

8vCPUs. 16 GB

D.

2vCPUs.4GB

Buy Now
Questions 106

How is a TLOC uniquely identified from a WAN Edge router to the SD-WAN transport network?

Options:

A.

system IP address

B.

VPN ID

C.

OMP

D.

SD-WAN site ID

Buy Now
Questions 107

Which two products are used to deploy Cisco WAN Edge Router virtual platforms? (Choose two.)

Options:

A.

HP ProLiant DL360 Generatton10 running HP-UX

B.

Cisco ENCS 5000 Series

C.

Sun SPARC Node running AIX

D.

Cisco UCS

E.

Sun Enterprise M4000 Server running Sun Solans

Buy Now
Questions 108

Drag and drop the actions from the left into the correct sequence on the right to create a data policy to direct traffic to the Internet exit.

300-415 Question 108

Options:

Buy Now
Questions 109

Which controller is excluded from the process of checking against the authorized, allowed list?

Options:

A.

vBond

B.

PnP

C.

vSmart

D.

vManage

Buy Now
Questions 110

A Cisco SD-WAN customer has a requirement to calculate the SHA value for files as they pass through the device to see the returned disposition and determine if the file is good, unknown or malicious. The customer also wants to perform real-time traffic analysis and generate alerts when threats are detected Which two Cisco SD-WAN solutions meet the requirements? (Choose two.)

Options:

A.

Cisco Trust Anchor Module

B.

Cisco Threat Grid

C.

Cisco Snort IPS

D.

Cisco AMP

E.

Cisco Secure Endpoint

Buy Now
Questions 111

An engineer is troubleshooting a vEdge router and identifies a “DCONFAIL – DTLS connection failure” message. What is the problem?

Options:

A.

certificate mismatch

B.

organization mismatch

C.

memory issue

D.

connectivity issue

Buy Now
Questions 112

Which component is responsible for creating and maintaining the secure DTLS/TLS connection on the vSmart controller?

Options:

A.

SNMP

B.

vdaemon

C.

NETCONF

D.

OMP

Buy Now
Questions 113

Which two protocols are supported for software image delivery when images are hosted on a remote server? (Choose two.)

Options:

A.

HTTPS

B.

SSL

C.

HTTP

D.

TFTP

E.

FTP

Buy Now
Questions 114

300-415 Question 114

300-415 Question 114

Refer to the exhibit The Cisco SD-WAN network is configured with a default full-mesh topology. Islamabad HQ and Islamabad WAN Edges must be used as the hub sites. Hub sites MPLS TLOC must be preferred when forwarding FTP traffic based on a configured SLA class list. Which policy configuration does the network engineer use to call the SLA class and set the preferred color to MPLS?

Options:

A.

Localized Policy, Route Policy

B.

Centralized Policy, Traffic Policy

C.

Localized Policy, Forwarding Class

D.

Centralized Policy Topology

Buy Now
Questions 115

300-415 Question 115

Refer to the exhibit Which command allows traffic through the IPsec tunnel configured in VPN 0?

Options:

A.

service local

B.

service FW address 1.1.1.1

C.

service netsvc1 vpn 1

D.

service netsvc1 address 1.1.1.1

Buy Now
Questions 116

300-415 Question 116

Refer to the exhibit. The network administrator has configured a centralized topology policy that results in the displayed routing table at a branch office. Which two configurations are verified by the output? [Choose two.)

Options:

A.

The routing table is for the transport VPN.

B.

The default route is learned via OMP.

C.

This routing table is from a cEdge router.

D.

The default route is configured locally.

E.

The configured policy is adding a route tag of 300 to learned routes.

Buy Now
Questions 117

What are the two components of an application-aware firewall? (Choose two.)

Options:

A.

zone pair

B.

sequence

C.

lists

D.

default action

E.

sequence action

F.

firewall policy

Buy Now
Questions 118

Refer to the exhibit.

300-415 Question 118

The network team must configure branch B WAN Edge device 103 to establish dynamic full-mesh IPsec tunnels between all colors with branches over MPLS and Internet circuits. The branch ts configured with:

300-415 Question 118

300-415 Question 118

Which configuration meets the requirement?

A)

300-415 Question 118

B)

300-415 Question 118

C)

300-415 Question 118

D)

300-415 Question 118

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 119

An engineer must configure a centralized policy on a site in which all HTTP traffic should use the Public Internet circuit if the loss on this circuit is below 10%. otherwise MPLS should be used Which configuration wizard fulfils this requirement?

Options:

A.

Create Applications or Groups of Interest > Configure Traffic Rules > Apply Policies to Sites and VPNs

B.

Configure VPN Membership > Apply Policies to Sites and VPNs

C.

Create Applications or Groups of interest > Configure Traffic Data > Apply Policies to Sites and VPNs

D.

Configure Topology > Apply Policies to Sites and VPNs

Buy Now
Questions 120

300-415 Question 120

Refer to the exhibit Which configuration ensures that OSPF routes learned from Site2 are reachable at Sitel and vice-versa?

300-415 Question 120

300-415 Question 120

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 121

An engineer is adding a tenant with location JD 306432373 in vManage. What is the maximum number of alphanumeric characters that are accepted in the tenant name field?

Options:

A.

64

B.

128

C.

256

D.

8

Buy Now
Questions 122

Which two features does the application firewall provide? (Choose two.)

Options:

A.

classification of 1400+ layer 7 applications

B.

blocks traffic by application or application-family

C.

numbered sequences of match-action pairs

D.

classification of 1000+ layer 4 applications

E.

application match parameters

Buy Now
Questions 123

An engineer is applying QoS policy for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router Which command accomplishes the task?

Options:

A.

cloud-qos-service-side

B.

qos-scheduler QOS_0

C.

qos-map QOS

D.

rewrite-rule QOS-REWRITE

Buy Now
Questions 124

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Buy Now
Questions 125

An engineer provisions a WAN Edge router. Which command should be used from the WAN Edge router to activate it with vManage?

Options:

A.

request vedge-cloud activate serial token

B.

request vedge-cloud activate chassis-number organization

C.

request vedge-cloud activate chassis-number token

D.

request vedge-cloud activate chassis-number serial <:serial>

Buy Now
Questions 126

Which TLOC color is used for site-to-site communication in a Google Cloud integration with Cisco SD-WAN?

Options:

A.

Private1

B.

private2

C.

private3

D.

private4

Buy Now
Questions 127

Which platform is a Cisco SD-WAN virtual platform?

Options:

A.

Cisco ISR 4000

B.

Cisco Nexus 1000V

C.

Cisco CSR 1000V

D.

Cisco ASR 1000

Buy Now
Questions 128

Drag and drop the alarm states from the left onto the corresponding alarm descriptions on the right.

300-415 Question 128

Options:

Buy Now
Questions 129

300-415 Question 129

Refer to the exhibit The network team must configure ElGRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

300-415 Question 129

Which configuration on the WAN Edge meets the requiremnet

A)

300-415 Question 129

B)

300-415 Question 129

C)

300-415 Question 129

D)

300-415 Question 129

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 130

A network administrator is configuring a centralized control policy based on match action pairs for multiple conditions, which order must be configured to prefer Prefix List over TLOC and TLOC over Origin?

Options:

A.

highest to lowest sequence number

B.

nonsequential order

C.

deterministic order

D.

lowest to highest sequence number

Buy Now
Questions 131

A policy is created to influence routing path in the network using a group of prefixes. What policy application will achieve this goal when applied to a site List?

Options:

A.

vpn-membership policy

B.

cflowd-template

C.

app-route policy

D.

control-policy

Buy Now
Questions 132

Which encryption algorithm secures binding exchanges Between Cisco TrustSec SXP peers?

Options:

A.

SEAL

B.

3DES

C.

AES

D.

MD5

Buy Now
Exam Code: 300-415
Exam Name: Implementing Cisco SD-WAN Solutions (300-415 ENSDWI)
Last Update: Dec 5, 2025
Questions: 441

PDF + Testing Engine

$144.99

Testing Engine

$109.99

PDF (Q&A)

$94.99