Question 1:

Which attributes are configured to uniquely identify and represent a TLOC route?

A. system IP address, link color, and encapsulation

B. origin, originator, and preference

C. site ID, tag, and VPN

D. firewall, IPS, and application optimization

Correct Answer: A

TLOC routes are the logical tunnel termination points on the vEdge routers that connect to a transport network. A TLOC route is uniquely identified and represented by a three-tuple, consisting of system IP address, link color, and encapsulation (Generic Routing Encapsulation [GRE] or IPSec). In addition to system IP address, color, and encapsulation, TLOC routes also carry attributes such as TLOC private and public IP addresses, carrier, preference, site ID, tag, and

weight. For a TLOC to be considered in an active state on a particular vEdge, an active BFD session must be associated with that vEdge TLOC. https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/SDWAN/CVD-SD-WAN-Design-2018OCT.pdf

Question 2:

Which command displays BFD session summary information per TLOC on vEdge routers?

A. show bfd tloc-summary-list

B. show bfd history

C. show bfd summary

D. show bfd sessions

Correct Answer: A

Reference: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/command/sdwan-cr-book/sdwan-cr-book_chapter_0100.html#wp5111537210

Question 3:

Which routing protocol is used to exchange control plane information between vSmart controllers and WAN Edge routers in the Cisco SD-WAN secure extensible network?





Correct Answer: D

Reference: https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/sd-wan/nb-06-cisco-sd-wan-ebook-cte-en.pdf

Question 4:

In the Cisco SD-WAN solution, the vSmart controller is responsible for which two actions? (Choose two)

A. Authenticate and authorize vEdge routers.

B. Distribute the IP address from the DHCP server to vEdge routers

C. Distribute crypto key information among vEdge routers

D. Configure and monitor vEdge routers

E. Distribute route and policy information via OMP.

Correct Answer: CE

Question 5:

An engineering team must prepare a traffic engineering policy where an MPLS circuit is preferred for traffic coming from the Admin VLAN. Internet should be used as a backup only. Which configuration fulfills this requirement?

latest 300-415 questions 5

A. Option A

B. Option B

C. Option C

D. Option D

Correct Answer: B

Question 6:

Refer to the exhibit.

latest 300-415 questions 6

Which configuration configures IPsec tunnels in active and standby?

latest 300-415 questions 6-1

A. Option A

B. Option B

C. Option C

D. Option D

Correct Answer: C

Question 7:

What is the behavior of the vBond orchestrator?

A. It builds permanent connections with vSmart controllers.

B. It builds permanent connections with WAN Edge routers.

C. It updates vSmart of WAN Edge routers behind NAT devices using OMP.

D. It maintains vSmart and WAN Edge routers secure connectivity state.

Correct Answer: D

Reference: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/system-overview.html

Question 8:

When redistribution is configured between OMP and BGP at two Data Center sites that have Direct Connection Interlink, which step avoids learning the same routes on WAN Edge routers of the DCs from LAN?

A. Set down-bit on Edge routers on DC1

B. Define different VRFs on both DCs

C. Set OMP admin distance lower than BGP admin distance

D. Set the same overlay AS on both DC WAN Edge routers

Correct Answer: D

Question 9:

Refer to the exhibit.

latest 300-415 questions 9

Which configuration stops Netconf CLI logging on WAN Edge devices during migration?

latest 300-415 questions 9-1

A. Option A

B. Option B

C. Option C

D. Option D

Correct Answer: B


latest 300-415 questions 9-2

Question 10:

What is the benefit of the application-aware firewall feature in the Cisco SD-WAN solution?

A. application monitoring

B. application malware protection

C. application visibility

D. control policy enforcement

Correct Answer: C


Question 11:

Refer to the exhibit.

latest 300-415 questions 11

Which command allows traffic through the IPsec tunnel configured in VPN 0?

A. service netsvc1 vpn1

B. service netsvc1 address

C. service FW address

D. service local

Correct Answer: B

Reference: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/policies/vedge-20-x/policies-book/service-chaining.html

Question 12:

Refer to the exhibit. An engineer is troubleshooting a control connection issue. What does “connect” mean in this show control connections output?

latest 300-415 questions 12

A. Control connection is down

B. Control connection is up

C. Control connection attempt is in progress

D. Control connection is connected

Correct Answer: C

Reference: https://community.cisco.com/t5/networking-documents/sd-wan-routers-troubleshoot-control-connections/ta-p/3813237

Question 13:

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?


B. vSmart

C. vManage

D. vBond

Correct Answer: C

Question 14:

Which issue triggers the Cisco Umbrella resolver toward DNS requests to the intelligent proxy?

A. A domain is nonexistent.

B. A domain is block-listed.

C. A domain is locally reachable.

D. A domain is grey-listed.

Correct Answer: D

Question 15:

Refer to the exhibit vManage and vBond have an issue establishing a connection with each other Which action resolves the issue?

latest 300-415 questions 15
latest 300-415 questions 15-1

A. Change the organization name on both controllers to match viptela.com.

B. Configure the encapsulation ipsec command under the tunnel interface on vManage.

C. Reconfigure the system IPs to belong to the same subnet.

D. Remove the encapsulation ipsec command under the tunnel interface of vBond.

Correct Answer: A

Reference: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/cisco-sd-wan-overlay-network-bringup.html

