Spring Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: spcl70

Practice Free 300-415 Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the Cisco 300-415 Exam the most current and reliable questions . To help people study, we've made some of our Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) exam materials available for free to everyone. You can take the Free 300-415 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

An engineer is applying QoS policy for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router Which command accomplishes the task?

A.

cloud-qos-service-side

B.

qos-scheduler QOS_0

C.

qos-map QOS

D.

rewrite-rule QOS-REWRITE

Question # 7

An enterprise has these three WAN connections:

public Internet

business internet

MPLS

An engineer must configure two available links to route traffic via both links. Which configuration achieves this objective?

300-415 question answer

A.

Option

B.

Option

C.

Option

D.

Option

Question # 8

A customer has 1 to 100 service VPNs and wants to restrict outbound updates for VPN1 Which control policy configuration restricts these updates?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 9

What is the purpose of ‘’vpn 0’’ in the configuration template when onboarding a WAN edge node?

A.

It carries control traffic over secure DTLS or TLS connections between vSmart controllers and vEdge routers, and between vSmart and vBond

B.

It carries control out-of-band network management traffic among the Viptela devices in the overlay network.

C.

It carries control traffic over secure IPsec connections between vSmart controllers and vEdge routers, and between vSmart and vManager

D.

It carries control traffic over secure IPsec connections between vSmart controllers and vEdge routers, and between vSmart and vBond

Question # 10

An engineer must advertise OSPF-learned routes and modify the update interval for route filtering by TLOC color to 300 on an SD-WAN device. Which configuration accomplishes this

task?

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 11

What is a requirement for a WAN Edge to reach vManage, vBond, and vSmart controllers in a data center?

A.

IGP

B.

QoS

C.

TLS

D.

OMP

Question # 12

Which configuration changes the packet loss priority from low to highly?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 13

How many concurrent sessions does a vManage REST API have before it invalidates the least recently used session if the maximum concurrent session number is reached?

A.

150

B.

200

C.

250

D.

300

Question # 14

In Cisco SD-WAN, what protocol is used for control connections between SD-WAN devices?

A.

DTLS

B.

OMP

C.

BGP

D.

OSPF

Question # 15

Which component of the Cisco SD-WAN control plane architecture should be located in a public Internet address space and facilitates NAT-traversal?

A.

vBond

B.

WAN Edge

C.

vSmart

D.

vManage

Question # 16

Company ABC has decided to deploy the controllers using the On-Prem method. How does the administrator upload the WAN Edge list to the vManage?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 17

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Question # 18

Drag and drop the devices from the left onto the correct functions on the right.

300-415 question answer

Question # 19

An engineer creates this data policy for DIA for VPN 10:

300-415 question answer

Which policy sequence enables DIA for external networks?

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 20

Drag and drop the actions from the left into the correct sequence on the right to create a data policy to direct traffic to the Internet exit.

300-415 question answer

Question # 21

How many cloud gateway instance(s) can be created per region when provisioning Cloud OnRamp for Multicloud from AWS in a multiregion environment?

A.

one

B.

two

C.

three

D.

four

Question # 22

300-415 question answer

Refer to the exhibit An engineer must configure a QoS policy between me hub and site A (spoke) over a standard internet circuit where traffic shaping is adjusted automatically based on evaiiabk» bandwidth Which configuration meets the requirement?

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 23

300-415 question answer

Refer to the exhibit. A customer wants to deploy service insertion at site1. Which traffic from VPN 10 must route to this site through a firewall. A policy must be in place to route VPN 10 traffic from all sites toward this firewall. Which configuration must be on the vSmart controller to meet this requirement?

A.
B.
C.
D.
Question # 24

Refer to the exhibit.

300-415 question answer

The control connection is failing. Which action resolves the issue?

A.

import vSmart in vManager

B.

Validate the certificates authenticity on vSmart

C.

Upload the WAN Edge list on vManage.

D.

Restore the reachability to the vSmart

Question # 25

An application team is getting ready to deploy a new business-critical application to the network. To protect the traffic, the network team must add another queue to the QoS map and then deploy the map to fabric Which configuration slop must be completed prior to adding the queue to the QoS map and applying If

A.

The relationship between die new QoS class and the hardware queue must be configured from the 'lists' page of the Local Policy section of vManage. The QoS map is then applied to the WAN interface

B.

The relationship between The new QoS class and the hardware queue must be configured from the 'lists' page of the Local Policy section of vManage. The QoS map is then applied to the service-side interface.

C.

The relationship between the new QoS class and the hardware queue must be configured from the "lisla" page of the Centralized Policy section of vManage. The QoS map is then applied to the WAN interface.

D.

The relationship between the new QoS class and the hardware queue must be configured from the "lists" page of the Centralized Policy section of vManage. The QoS map is then applied to the service-side interface.

Question # 26

300-415 question answer

Refer to the exhibit A user has selected the options while configuring a VPN Interface Ethernet feature template What is the required configuration parameter the user must set in this template for this feature to function?

A.

The "IP MTU" field must be increased from the default value of 1500 to support the additional overhead.

B.

The "Shaping Rate (Kbps)" field must be configured with a value

C.

The "Adaptive QoS" field must be set to "on"

D.

The "Bandwidth Downstream" field must be configured with a value

Question # 27

Refer to the exhibit.

300-415 question answer

What binding is created using the tloc-extension command?

A.

between ge 0/2.101 of port-type service and ge 0/0 of port-type service

B.

between ge 0/2.101 of port-type transport and ge 0/0 of port-type service

C.

between ge 0/2.101 of port-type service and ge 0/0 of port-type transport

D.

between ge 0/2.101 of port-type transport and ge 0/0 of port-type transport

Question # 28

What is the procedure to upgrade all Cisco SD-WAN devices to a recent version?

A.

The upgrade is performed for a group of WAN Edge devices first to ensure data-plabe availability when other controllers are updated.

B.

The upgrade is performed first on vManage, then on WAN Edge devices, then on vBond and finally on vSmart The reboot must start from WAN Edge devices.

C.

Upgrade and reboot are performed first on vManage then on vBond then on vSmart. and finally on the Cisco WAN Edge devices.

D.

Upgrade and reboot are performed first on vBond. then on vSmart. and finally on the Cisco WAN Edge devices.

Question # 29

Drag and drop the vManage policy configuration procedures from the left onto the correct definitions on the right.

300-415 question answer

Question # 30

Which two sets of identifiers does OMP carry when it advertises TLOC routes between WAN Edge routers? (Choose two.)

A.

TLOC public and private address, carrier, and preference

B.

source and destination IP address, MAC, and site ID

C.

system IP address, link color, and encapsulation

D.

VPN ID, local site network, and BGP next-hop IP address

E.

TLOC public and private address, tunnel ID, and performance

Question # 31

Which two vRoute attributes should be matched or set in vSmart policies and modified by data policies? (Choose two.)

A.

site ID

B.

preference

C.

VPN

D.

TLOC

E.

origin

Question # 32

An engineer must configure two branch WAN Edge devices where an Internet connection is available and the controllers are in the headquarters. The requirement is to have IPsec VPN tunnels established between the same colors. Which configuration meets the requirement on both WAN Edge devices?

300-415 question answer

300-415 question answer

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 33

Which compression algorithm does DRE use in a Cisco SD-WAN environment?

A.

run-length encoding

B.

Lempel-Ziv-Welch encoding

C.

Ziv Huffman encoding

D.

Huffman encoding

Question # 34

A company deploys a Cisco SD-WAN solution but has an unstable Internet connection. When the link to vSmart comes back up, the WAN Edge router routing table is not refreshed, and some traffic to the destination network is dropped. The headquarters is the hub site, and it continuously adds new sites to the SD-WAN network. An engineer must configure route refresh between WAN Edge and vSmart within 2 minutes. Which configuration meets this requirement?

300-415 question answer

A.

Option A

B.

B

C.

Option B

D.
E.

Option C

F.

Option D

Question # 35

300-415 question answer

Refer to the exhibit. Which configuration stops Netconf CLI logging on WAN Edge devices during migration?

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 36

Which plane assists in the automatic onboarding of the SD-WAN routers into the SD-WAN overlay?

A.

Data

B.

Orchestration

C.

Management

D.

Control

Question # 37

What happens if the intelligent proxy is unreachable in the Cisco SD-WAN network?

A.

The grey-listed domains are unresolved

B.

The Cisco Umbrella Connector locally resolves the DNS request

C.

The block-listed domains are unresolved

D.

The Cisco Umbrella Connector temporarily redirects HTTPS traffic

Question # 38

300-415 question answer

Refer to the exhibit A vBond controller was added to the controller list with the same Enterprise Root CA certificate as vManage. The two controllers can reach each other via VPNO and share the same organization name, but the control connection is not initiated- Which action resolves the issue?

A.

Synchronize the WAN Edge list on vManage with controllers.

B.

Configure NTP on both controllers to establish a connection.

C.

Configure a valid systom IP on the vBond controller.

D.

Configure a valid vBond IP on vManage.

Question # 39

Refer to the exhibit.

300-415 question answer

The engineer must assign community tags to 3 of its 74 critical server networks as soon as that are advertised to BGP peers. These server networks must not be advertised outside AS. Which configuration fulfill this requirement?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 40

Which queue must an engineer configure for control and BFD traffic for convergence on a WAN Edge router?

A.

queue 0

B.

queue 1

C.

queue 2

D.

queue 7

Question # 41

What is the threshold to generate a warning alert about CPU or memory usage on a WAN Edge router?

A.

70 to 85 percent

B.

70 to 90 percent

C.

75 to 85 percent

D.

75 to 90 percent

Question # 42

Which routing protocol has the highest default administrative distance?

A.

OMP

B.

external EIGRP

C.

IS-IS

D.

IBGP

Question # 43

300-415 question answer

Refer to the exhibit. An engineer is troubleshooting a control connection issue on a WAN Edge device that shows socket errors. The packet capture shows some ICMP packets dropped between the two devices. Which action resolves the issue?

A.

Recover the vManage controller that is down m a high availability cluster

B.

Change the system IP or restart the VWN Edge 4 the system IP is changed

C.

Remove IP duplication in the network and configure a unique IP address

D.

Recover vBond or wart for the controller to reload which could be caused by a reset

Question # 44

What is the ZTP workflow for Cisco IOS XE-based devices?

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 45

Drag and drop the alarm slates from the left onto the corresponding alarm descriptions on the right.

300-415 question answer

Question # 46

Which plane builds and maintains the network topology and makes decisions on traffic flows?

A.

orchestration

B.

management

C.

control

D.

data

Question # 47

300-415 question answer

Refer to the exhibit. A Cisco SD-WAN network carries traffic for several departments and over 1200 users with several applications at site A and site B branches over the MPLS1 circuit. An engineer is provisioning a higher bandwidth on-demand metro circuit as a backup connection. Which two configurations must the engineer apply to implement the on-demand tunnels? (Choose two.)

A.
B.
C.
D.
E.
Question # 48

300-415 question answer

Refer to the exhibit, which configuration configures IPsec tunnels in active and standby?

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 49

300-415 question answer

300-415 question answer

Refer to the exhibit The Cisco SD-WAN network is configured with a default full-mesh topology. Islamabad HQ and Islamabad WAN Edges must be used as the hub sites. Hub sites MPLS TLOC must be preferred when forwarding FTP traffic based on a configured SLA class list. Which policy configuration does the network engineer use to call the SLA class and set the preferred color to MPLS?

A.

Localized Policy, Route Policy

B.

Centralized Policy, Traffic Policy

C.

Localized Policy, Forwarding Class

D.

Centralized Policy Topology

Question # 50

Which logs verify when a device was upgraded?

A.

Audit

B.

Email

C.

ACL

D.

SNMP

Question # 51

An engineer creates a data policy to prevent communication from the 172.20.21.0/24 network to the 172.20.41.0/24 network. Which configuration accomplishes this task?

300-415 question answer

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 52

In which device state does the WAN edge router create control connections, but data tunnels are not created?

A.

valid

B.

backup

C.

active

D.

staging

Question # 53

An SD-WAN customer must ensure that its network operations team can monitor and update the NTP server if needed on a WAN Edge in HQ. Which configuration meets this requirement?

A.

system

usergroup operator

task interface write

B.

system

aaa

usergroup operator

task policy write

C.

system

aaa

usergroup operator

task system write

D.

system

aaa

usergroup operator

task security write

Question # 54

An engineer is tasked to improve throughput for connection-oriented traffic by decreasing round-trip latency. Which configuration will achieve this goal?

A.

turn on "Enable TCP Optimization"

B.

turn off "Enhance ECMP Keying"

C.

turn off "Enable TCP Optimization"

D.

turn on "Enhance ECMP Keying"

Question # 55

Refer to exhibit.

300-415 question answer

An engineer is troubleshooting tear down of control connections even though a valid Certificate Serial Number is entered Which two actions resolve the Issue? (Choose two)

A.

Enter a valid serial number on the controllers for a given device

B.

Remove the duplicate IP in the network.

C.

Enter a valid product ID (model) on the PNP portal

D.

Match the serial number file between the controllers

E.

Restore network reachability for the controller

Question # 56

An engineer is configuring a list that matches all IP prefixes with lengths from /1 to /16 in a centralized control policy. Which list accomplishes this task?

A.

0.0.0.0/1 le 16

B.

0.0.0.0/0 ge 1

C.

0.0.0.0/0 le l6

D.

0.0.0.0/16 ge 1

Question # 57

A voice packet requires a latency of 50 msec. Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?

A.

centralized control

B.

localized data

C.

localized control

D.

centralized data

Question # 58

If Smart Account Sync is not used, which Cisco SD-WAN component is used to upload an authorized serial number file?

A.

WAN Edge

B.

vManage

C.

vSmart

D.

vBond

Question # 59

What are the default username and password for vSmart Controller when it is installed on a VMware ESXi hypervisor'?

A.

username Cisco password admin

B.

username admin password Cisco

C.

username Cisco password Cisco

D.

username admin password admin

Question # 60

Which two products that perform lifecycle management for virtual instances are supported by WAN Edge cloud routers? (Choose two.)

A.

OpenStack

B.

AWS

C.

VMware vCenter

D.

Azure

E.

IBM Cloud

Question # 61

Refer to the exhibit.

300-415 question answer

A customer wants to implement primary and secondary Cisco SD-WAN overlay routing for prefixes that are advertised for both data centers. The east data center (TLOC 101.101.101.101) is primary for east sites, and the west data center (TLOC 100.100.100.100) is primary for west sites. Which configuration change achieves this objective?

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 62

300-415 question answer

Refer to the exhibit. An engineer configures a hub-and-spoke SD-WAN topology with the requirement that traffic from router A branch to router B branch is guaranteed to flow through the network hub, router C. Which configuration meets the requirement for router A?

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 63

Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?

A.

OMP outside the DTLS/TLS control connection

B.

BGP inside the DTLS/TLS

C.

IPsec inside the DTLS/TLS control connection

D.

OMP inside the DTLS/TLS control connection

Question # 64

What is the main purpose of using TLOC extensions in WAN Edge router configuration?

A.

creates hardware-level transport redundancy at the local site

B.

creates an IPsec tunnel from WAN Edge to vBond Orchestrator

C.

transports control traffic to a redundant vSmart Controller

D.

transports control traffic w remote-site WAN Edge routers

Question # 65

Drag and drop the steps from the left into the order on the right to upload software on vManage repository that is accessible from maintenance > Software Repository.

300-415 question answer

Question # 66

A network administrator configures SNMPv3 on a Cisco WAN Edge router from CLI for monitoring purposes How many characters are supported by the snmp user command?

A.

from 1 to 8

B.

from 1 to 16

C.

from 1 to 32

D.

from 1 to 48

Question # 67

On which device is a service FW address configured to Insert firewall service at the hub?

A.

vEdge at the branch

B.

vSmart at the hub

C.

vEdge at the hub

D.

vSmart at the branch

Question # 68

300-415 question answer

Refer to the exhibit vManage and vBond have an issue establishing a connection to vSmart Which two actions does the administrator take to fix the issue? (Choose two)

A.

Install the certificate received from the certificate server.

B.

Manually resync vManage and vBond

C.

Reconfigure the vSmart from CLI with the proper Hostname & System IP

D.

Delete and re-add vSmart Click Generate and validate CSR

E.

Request a certificate from the certificate server based on the CSR for the vSmart

Question # 69

An enterprise has several sites with multiple VPNs that are isolated from each other A new requirement came where users in VPN 73 must be able to talk to users in VPN 50 Which configuration meets this requirement?

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 70

300-415 question answer

Refer to the exhibit A WAN Edge device was recently added to vManage but a control connection could not be established Which action resolves this issue?

A.

Rectify the Rod CA certificate mismatch on WAN Edge devices

B.

Install the bootstrap code on WAN Edge and check for CSR

C.

Send the serial number to vBond from the vManage controller.

D.

Resolve the ZTP reachability and rectify smart account credentials issue

Question # 71

The Cisco SD-WAN engineer is configuring service chaining for a next-generation firewall located at the headquarters. Which configuration creates the service?

A)

300-415 question answer

B)

C)300-415 question answer

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 72

Drag and drop the alarm states from the left onto the corresponding alarm descriptions on the right.

300-415 question answer

Question # 73

Which protocol is used to measure jitter, loss, and latency on SD-WAN overlay tunnels?

A.

QoE

B.

OMP

C.

BGP

D.

BFD

Question # 74

Customer has two branch silos with overlapping IPs How must the data policy be configured to establish communication between the sites and server to avoid overlapping?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 75

A network administrator is configuring Qos on a vEdge 5000 router and needs to enable it on the transport side interface. Which policy setting must be selected to accomplish this goal?

A.

Cloud QoS Service side

B.

Cloud QoS

C.

NetFlow

D.

Application

Question # 76

How is an event monitored and reported for an individual device in the overlay network at site ID:S4300T6E43F36?

A.

The device sends event notifications to vManage.

B.

The device sends notifications to vSmart that sends them to vManage.

C.

The device sends a critical alarm of events to vManage.

D.

The device sends a critical alarm to vSmart that sends it to vManage.

Question # 77

300-415 question answer

Refer to the exhibit. Which configuration ensures that OSPP routes learned from Site2 are reachable at Stein and vice-versa?

A.
B.
C.
Question # 78

What are the two advantages of deploying cloud-based Cisco SD-WAN controllers? (Choose two.)

A.

centralized control and data plane

B.

distributed authentication policies

C.

management of SLA

D.

infrastructure as a service

E.

centralized raid storage of data

Question # 79

300-415 question answer

Refer to the exhibit. An engineer must configure the Overlay Management Protocol route preference so that when B2 tries to reach host routes advertised by B1 it always chooses the MPLS circuit. Which two match conditions must be configured to accomplish this task? (Choose two.)

A.

VPN

B.

prefix list

C.

originator

D.

color list

E.

path type

Question # 80

An engineer modifies a data policy for DIA in VPN 67. The location has two Internet-bound circuits. Only the web browsing traffic must be admitted for DIA. without further discrimination about which transport to use.

Here is the existing data policy configuration:

300-415 question answer

Which policy configuration sequence meets the requirements?

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 81

300-415 question answer

Refer to the exhibit. The ge0/0 interface connects to a 30-MB link. A network administrator wants to always have 10 MB available for high priority traffic. When lower-priority traffic busts exceed 20 MB. Traffic should be redirected to the second WAN interface ge0/1. Which set of configurations accomplishes this task?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 82

An organization wants to discover monitor and track the applications running on the WAN Edge device on the LAN Which configuration achieves this goal?

300-415 question answer

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 83

Which component of the Cisco SD-WAN control plane architecture facilitates the storage of certificates and configurations for network components?

A.

vSmart

B.

vBond

C.

WAN Edge

D.

vManage

Question # 84

An engineer modifies a data policy for DIA in VPN 200 to meet the requirements for traffic destined to these locations:

* external networks; must be translated

* external networks; must use a public TLOC color

* syslog servers, must use a private TLOC color

Here is the existing data policy configuration:

300-415 question answer

Which policy configuration sequence set meets the requirements?

A.
B.
C.
Question # 85

Refer to the exhibit.

300-415 question answer

An enterprise has enabled load balancing over MPLS and Internet links. Which feature from the monitoring tool does an engineer use to visualize the available links utilized by the data traffic between Service VPNs?

A.

Simulate Flows

B.

App Route Visualization

C.

Top Talkers

D.

Control Connections (Live View)

Question # 86

Which destination UDP port is used by WAN Edge router to make a DTLS connection with vBond Orchestrator?

A.

12343

B.

12345

C.

12346

D.

12347

Question # 87

Which policy configures an application-aware routing policy under Configuration > Policies?

A.

Localized policy

B.

Centralized policy

C.

Data policy

D.

Control policy

Question # 88

An engineer is configuring a shaping rate of 1 Mbps on the WAN link of a WAN Edge router Which configuration accomplishes this task’?

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 89

A company must avoid downtime at the remote sites and data plane to continue forwarding traffic between WAN Edge devices if the branch router loses connectivity to its OMP peers Which configuration meets the requirement?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 90

Which platforms are managed by a single vManage dashboard?

A.

ISR4351, ASR1002HX, vEdge2000, vEdge Cloud

B.

ISR4321, ASR1001, Nexus, ENCS

C.

ISR4321, ASR1001, ENCS, ISRv

D.

ISR4351, ASR1009, vEdge2000, CSR1000v

Question # 91

What are the two components of an application-aware firewall? (Choose two.)

A.

zone pair

B.

sequence

C.

lists

D.

default action

E.

sequence action

F.

firewall policy

Question # 92

How many vManage NMSs should be installed in each domain to achieve scalability and redundancy?

A.

two instances

B.

two clusters

C.

three or more in a cluster

D.

two or more in a cluster

Question # 93

An engineer must create a QoS policy by creating a class map and assigning it to the LLQ queue on a WAN Edge router Which configuration accomplishes the task?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 94

What is the advantage of instating the controller on-premises?

A.

ease of deployment and management

B.

full control of the data piano and the control plane

C.

automatic geographical redundancy and security

D.

scalability and a cost-saving

Question # 95

An engineer is configuring a centralized policy to influence network route advertisement. Which controller delivers this policy to the fabric?

A.

vSmart

B.

vManage

C.

WAN Edge

D.

vBond

Question # 96

Which component of the Cisco SD-WAN architecture oversees the control plane of overlay network to establish, adjust, and maintain the connections between the WAN Edge devices that form the Cisco SD-WAN fabric?

A.

APIC-EM

B.

vManage

C.

vSmart

D.

vBond

Question # 97

An engineer must avoid routing loops on the SD-WAN fabric for routes advertised between data center sites Which BGP loop prevention attribute must be configured on the routers to meet this requirement?

A.

same OMP overlay-as on WAN Edge routers of all data centers

B.

static routing on al WAN Edge routers instead of BGP

C.

same BGP AS between all WAN Edge routers and CE routers

D.

same BGP AS between all CE and PE routers

Question # 98

Which feature builds transport redundancy by using the cross link between two redundant WAN Edge routers?

A.

OMP

B.

zero-touch provisioning

C.

quality of service

D.

TLOC extension

Question # 99

When software is upgraded on a vManage NMS, which two image-adding options store images in a local vManage software repository? (Choose two.)

A.

To be downloaded over a SMTP connection

B.

To be downloaded over a SNMP connection

C.

To be downloaded over an out-of-band connection

D.

To be downloaded over a control plane connection

E.

To be downloaded over an ICMP connection

Question # 100

Which platform cannot provide IPS and URL filtering capabilities?

A.

Cisco CSR 1000V

B.

Cisco ISR 1000

C.

Cisco Catalyst 8300

D.

Cisco ISR 4000

Question # 101

An engineer must use data prefixes to configure centralized data policies using the vManage policy configuration wizard. What is the first step to accomplish this task?

A.

Create groups of interest

B.

Configure network topology.

C.

Configure traffic rules.

D.

Apply policies to sites and VPNs.

Question # 102

In which VPN is the NAT operation on an outgoing interface configured for direct Interne! access?

A.

1

B.

10

C.

512

D.

0

Question # 103

Which type of route advertisement of OMP can be verified?

A.

OMP, VPN. and origin

B.

Origin, TLOC, and VPN

C.

Origin, TLOC, and service

D.

OMP, TLOC and service

Question # 104

300-415 question answer

Refer to the exhibit. An enterprise decides to use the Cisco SD-WAN Cloud onRamp for SaaS feature and utilize H.Q site Biz iNET to reach SaaS Cloud for branch C. currently reaching SaaS Cloud directly. Which role must be assigned to devices at both sites in vManage Cloud Express for this solution to work?

A.

H.Q to be added as Gateway and Branch as DIA.

B.

Branch to be added as Client Sites and H.Q as DIA.

C.

Branch to be added as DIA and H.Q as Client Site.

D.

H.Q to be added as Gateway and Branch as Client Site.

Question # 105

Which value is verified in the certificates to confirm the identity of the physical WAN Edge device?

A.

Serial Number

B.

OTP

C.

System-IP

D.

Chassis-ID

Question # 106

Refer to the exhibit.

300-415 question answer

vManage and vSmart have an issue establishing a connection to vBond. Which configuration resolves the issue?

A.

Configure the tunnel interface on all three controllers with a color of transport.

B.

Change the timezone on the vSmart to Europe/London.

C.

Configure the (11.1.1.X/24) IP addresses on the elhO interfaces on vManage and vSmart.

D.

Reconfigure the system-ip parameter on vSmart to 11.1.1.2.

Question # 107

Which IP address must be reachable by a WAN Edge device for the ZIP process to work?

A.

10.1.1.1

B.

4.4 4.4

C.

172.16.1.1

D.

8.8.8.8

Question # 108

Refer to the exhibit.

300-415 question answer

The SD-WAN network is configured with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use MPLS TLOC as the preferred TLOC when communicating with Rome site. Which configuration must the engineer use to create a list to select MPLS color toward the Rome TLOC?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 109

At which layer does the application-aware firewall block applications on a WAN Edge?

A.

3

B.

7

C.

5

D.

2

Question # 110

Which device in the SD- WAN solution receives and categorizes event reports, and generates alarms?

A.

WAN Edge routers

B.

vSmart controllers

C.

vManage NMS

D.

vBond controllers

Question # 111

Drag and drop the steps from the left into the sequence on the right for a WAN Edge router after powering on for zero touch provisioning.

300-415 question answer

Question # 112

What problem happens on a device with two serial numbers, a unique device identifier (UDI), and secure unique device identifier (SUDI) when an engineer provisions ISR 4000 by PnP using only a UDI?

A.

It encounters spanning tree issues

B.

It faces interface buffer overflow patterns

C.

It encounters redirection problems.

D.

It encounters memory overload problems

Question # 113

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the primary device. What must be configured to get the fastest failover to standby?

A.

prefix-list tracking

B.

lower timer interval

C.

higher group ID number

D.

OMP tracking

Question # 114

When VPNs are grouped to create destination zone in Zone-Based Firewall, how many zones can a single VPN be part of?

A.

two

B.

four

C.

one

D.

three

Question # 115

A network engineer must configure all branches to communicate with each other through the Service Chain Firewall located at the headquarters site. Which configuration allows the engineer to accomplish this task?

A)

300-415 question answer

B)

300-415 question answer

C)

300-415 question answer

D)

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 116

Which vBond system configuration under VPN 0 allows for a routable public IP address even if the DNS name, hostname, or IP address of the vBond orchestrator are omitted?

A.

local

B.

vbond-only

C.

dns-name

D.

WAN

Question # 117

An engineer is modifying an existing data policy for VPN 115 to meet these additional requirements:

    When browsing government websites, the traffic must use direct internet access.

    The source address of the traffic leaving the site toward the government websites must be set to an IP range associated with the country itself, a particular TLOC.

The policy configuration is as follows:

300-415 question answer

Which policy sequence meets the requirements without interfering with other destinations?

A.

sequence 30

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

B.

sequence 25

match

destination-data-prefix-list GOVERNMENT-WEBSITES

action accept

nat use-vpn 0

C.

sequence 15

match

source-data-prefix-list GOVERNMENT-WEBSITES

action accept

set

local-tloc-list

color private1

D.

sequence 15

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

Question # 118

Which type of lists are used to group related items via an application-aware routing policy under the policy lists command hierarchy on vSmart controllers?

A.

data prefix, she. and VPN

B.

OSCP value, application, and VPN

C.

data prefix, application, and SLA class

D.

DSCP value, site, and VPN

Question # 119

Which two REST API functions are performed for Cisco devices in an overlay network? (Choose two)

A.

distributing a Snort image among devices

B.

attaching a device configuration template

C.

managing connections for smart licensing

D.

monitoring device certificates

E.

querying a device and aggregating statistics

Question # 120

Which timer specifies information in the cache after all OMP sessions are lost at location S0123T4E56F78?

A.

advertisement interval

B.

EOR timer

C.

graceful restart timer

D.

hold time

Question # 121

How do WAN Edge devices operate when vSmart is inaccessible or fails to be reached by the WAN Edge?

A.

They cease to forward traffic in the data plane.

B.

They continue operation normally.

C.

They continue to receive reachability updates.

D.

They continue operating normally for a configurable time.

Question # 122

How is TLOC defined?

A.

It is represented by a unique identifier to specify a site in as SD-WAN architecture.

B.

It specifies a Cisco SD-WAN overlay in a multitenant vSMART deployment.

C.

It is a unique collection of GRE or iPsec encapsulation, link color, and system IP address.

D.

It is represented by group of QoS policies applied to a WAN Edge router.

Question # 123

300-415 question answer

Refer to the exhibit. An ongineer configured OMP with an ovorlay-as of 10666. What is tho AS-PATH for prefix 104.104.104.104/32 on R1007?

A.

100 10666 104

B.

100 10666

C.

100 10666 20 104

D.

100 20 104

Question # 124

Which encryption algorithm is used for encrypting SD-WAN data plane traffic?

A.

Triple DES

B.

IPsec

C.

AES-128

D.

AES-256 GCM

Question # 125

A bank is looking for improved customer experience for applications and reduce overhead related to compliance and security. Which key feature or features of the Cisco SD-WAN solution will help the bank to achieve their goals?

A.

Integration with PaaS providers to offer the best possible application experience

B.

QoS including application prioritization and meeting critical applications SLA for selecting optimal path.

C.

implementation of a modem age core banking system

D.

implementation of BGP across the enterprise routing for selecting optimal path

Question # 126

Which platform is a Cisco SD-WAN virtual platform?

A.

Cisco ISR 4000

B.

Cisco Nexus 1000V

C.

Cisco CSR 1000V

D.

Cisco ASR 1000

Question # 127

Which component is used for stateful inspection of TCP, UDP. and ICMP flows in Cisco SD-WAN firewall policies?

A.

zones

B.

sites

C.

subnets

D.

interfaces

Question # 128

Refer to the exhibit.

300-415 question answer

300-415 question answer

vManage and vBond have an issue establishing a connection to each other. Which configuration resolves the issue?

A.

Configure the timezone on vBond to Europe/London.

B.

Configure the encapsulation ipsec command under the tunnel interface on vManage.

C.

Configure a default route on vBond pointing to 172.16.2.254.

D.

Remove the encapsulation ipsec command under the tunnel interface of vBond.

Question # 129

Drag and drop the definitions from the left to the configuration on the right.

300-415 question answer

Question # 130

Refer to the exhibit.

300-415 question answer

Which QoS treatment results from this configuration after the access list acl-guest is applied inbound on the vpn1 interface?

A.

A UDP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

B.

A TCP packet sourcing from 172.16.10.1 and destined to 172.16.20.1 is dropped

C.

A UDP packet souring from 172.16.10.1 and destined to 172.16.20.1 is dropped.

D.

A TCP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

Question # 131

A customer wants to use AWS for Cisco SD-WAN laaS services by deploying virtual SD-WAN routers in a transit AWS VPC The transit VPC then connects via site-to-site IPsec tunnels to an AWS transit gateway Which transit VPC connects via site-to-site IPsec tunnels to an AWS transit gateway?

A.

Cisco Cloud onRamp for Multicloud

B.

Cisco Cloud onRamp for SaaS

C.

Cisco Cloud onRamp for Colocation

D.

Cisco Cloud onRamp for laaS

Question # 132

Which command verifies a policy that has been pushed to the vEdge router?

A.

vEdge# show running-config data policy

B.

vEdge# show policy from-vsmart

C.

vSmart# show running-config policy

D.

vSmart# show running-config apply-policy

Question # 133

300-415 question answer

Refer to the exhibit, Which configuration routes Site 2 through the firewall in Site 1?

300-415 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

300-415 PDF

$42

$139.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

300-415 PDF + Testing Engine

$57

$189.99

3 Months Free Update

  • Exam Name: Implementing Cisco SD-WAN Solutions (300-415 ENSDWI)
  • Last Update: Mar 5, 2026
  • Questions and Answers: 446
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

300-415 Engine

$48

$159.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included