300-415 Sample Questions & Answers
Architecture, WAN Edge router rollout and control-and-data policy configuration are weighted equally heaviest, with the rest covering controller deployment, service insertion, cloud-security integration, and day-to-day operation from SD-WAN Manager.
Launch the full 300-415 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Routing · Route Redistribution between OMP and other routing protocols
An organization is migrating from a traditional WAN to Cisco SD-WAN. During the phased rollout, a branch site with a new vEdge router needs to communicate with a non-SD-WAN site that is only reachable via the MPLS network through a datacenter hub. The vEdge advertises its local subnets via OMP. How does the rest of the SD-WAN fabric learn about the legacy prefixes from the non-SD-WAN site?
Show answer & explanation
Correct answer: C
In a migration scenario, the hub or datacenter WAN Edge router acts as a gateway. It runs a traditional routing protocol (like BGP or OSPF) on its service side to learn routes from the legacy network. These learned routes are then redistributed into OMP, which advertises them to all other WAN Edge routers in the SD-WAN fabric, enabling connectivity.
- Question 2Beginner
Monitoring and Management · Application Quality of Experience (AppQoE)
A network administrator observes that a specific application is experiencing poor performance at a branch office. The application is hosted in a SaaS provider's cloud. The administrator wants to use vManage to identify the best-performing path (MPLS, Internet, or LTE) for this application without manually interpreting raw latency and jitter data. Which vManage feature provides this capability?
Show answer & explanation
Correct answer: C
The Application-Aware Routing (AAR) section within vManage, specifically its path visualization and AppQoE (Application Quality of Experience) metrics, is designed for this purpose. It calculates a quality score (vQoE) for applications across different paths based on measured loss, latency, and jitter, allowing an administrator to quickly identify the best-performing path and see if traffic is being steered correctly according to policy.
- Question 3Advanced
Policies · Hierarchical SD-WAN Design (Regions)
A global enterprise has deployed Cisco SD-WAN with regional hubs in North America, Europe, and Asia. To optimize routing, the architect has configured each region with its own vSmart controllers and has limited the scope of OMP route advertisements within each region. Which feature is used to achieve this hierarchical design and control route propagation between regions?
Show answer & explanation
Correct answer: C
The Hierarchical SD-WAN feature, often referred to as 'Regions', is specifically designed for this purpose. It allows an administrator to divide the overlay network into logical regions, with border routers (or regional hubs) controlling the advertisement of routes between regions. This significantly reduces the OMP routing table size on branch routers and provides a scalable, structured design.
- Question 4Beginner
Controller and WAN Edge Deployment · Zero Touch Provisioning (ZTP)
An engineer needs to deploy a new vEdge router at a remote site using Zero Touch Provisioning (ZTP). The router is powered on and connected to an internet circuit that provides a DHCP address. What is the first FQDN that the vEdge router will attempt to resolve to initiate the ZTP process?
Show answer & explanation
Correct answer: B
The first step in the ZTP process for a factory-default vEdge router is to resolve ztp.viptela.com. This DNS entry points to Cisco's Plug and Play (PnP) Connect portal, which will then authenticate the device based on its serial number and redirect it to the organization's specific vBond orchestrator address.
- Question 5Intermediate
Policies · Cloud OnRamp for SaaS
A company is using the Cisco SD-WAN Cloud onRamp for SaaS feature to optimize Office 365 performance. An administrator notices that traffic from a specific branch is not being sent directly to the Microsoft cloud via the local internet exit, but is instead being backhauled to the datacenter. A review of the SLA class in the application-aware routing policy shows that the DIA circuit meets the latency and loss requirements for Office 365.
What is the most likely cause of this behavior?
Show answer & explanation
Correct answer: D
Even if an application-aware routing policy determines that a direct internet path is optimal for SaaS traffic, a centralized data policy can override this decision. A common scenario is a data policy that matches specific application traffic and redirects it to a service (like a firewall or secure web gateway) located at a hub or datacenter using a 'service' action. This data policy would take precedence over the AAR policy's path selection.
- Question 6IntermediateSelect 2
Architecture · TLOC (Transport Locator)
Which two statements accurately describe the function of a TLOC in the Cisco SD-WAN architecture? (Choose two.)
Show answer & explanation
Correct answers: B, C
A TLOC serves as the logical endpoint in the SD-WAN overlay, representing the connection of a vEdge to a specific WAN provider (e.g., MPLS, Internet). It's the 'next-hop' in the OMP routing table.
This 3-tuple uniquely identifies a TLOC in the overlay. The System-IP identifies the router, the color identifies the specific WAN transport (e.g., mpls, biz-internet), and the encapsulation specifies the tunnel type (IPsec or GRE).
- Question 7Beginner
Management and Operations · Device Templates and Variables
An administrator is creating a device template in vManage for a fleet of cEdge routers located in branch offices. The branches have a mix of static and DHCP-based internet circuits. The administrator needs to define interface parameters that can be customized for each specific device when the template is attached. Which vManage feature should be used to accomplish this?
Show answer & explanation
Correct answer: B
Device-specific variables are placeholders (e.g., {{ip-address}}, {{gateway}}) created within a device template. When the template is attached to a device, vManage prompts the user to provide a value for each variable specific to that device. This allows a single template to be used for multiple devices with unique settings like IP addresses, hostnames, or interface descriptions.
- Question 8Intermediate
Security · Service Chaining / Service Insertion
A network security team requires that all internet-bound traffic from branch sites be inspected by a cloud-based Secure Web Gateway (SWG) service. The SD-WAN fabric is configured in a full-mesh topology. Which configuration provides the most scalable and efficient way to redirect this traffic to the SWG?
Show answer & explanation
Correct answer: B
The correct method is to use service chaining (also called service insertion). This is configured via a centralized data policy. You define the SWG as a 'service' and create a policy that matches internet-bound traffic (e.g., route to 0.0.0.0/0) and sets the next-hop to this service. This automatically creates secure tunnels from the WAN Edge routers to the SWG provider and redirects the specified traffic, which is a highly scalable and manageable approach.
- Question 9Intermediate
Troubleshooting · Control Connections and Certificates
An engineer is troubleshooting a control connection issue for a newly deployed vEdge router. The router fails to join the fabric. The engineer runs the command
show control local-propertiesand observes that the Certificate Status is 'Not-Installed'. What is the most likely reason for this status?Show answer & explanation
Correct answer: A
For a device to be considered valid and allowed to join the overlay, its chassis and serial number must be uploaded to vManage and associated with a certificate serial number. When the device attempts to join, vManage checks this list. If the device is not on the list, vManage will not authorize it, and the certificate will not be successfully installed, resulting in the 'Not-Installed' status.
- Question 10Advanced
Architecture · VPN Segmentation
A hospital is deploying a Cisco SD-WAN solution to connect its main campus with several remote clinics. Due to HIPAA compliance requirements, all traffic related to Electronic Health Records (EHR) must be logically isolated from guest Wi-Fi and facilities management traffic. All traffic types will share the same physical WAN links.
Company Background: The hospital has a central data center at the main campus where the EHR systems are hosted. Remote clinics need reliable access to these systems. Each clinic also provides a guest Wi-Fi network for patients.
Current Situation: The hospital uses a flat network architecture over MPLS, which provides no segmentation. They are migrating to a dual-transport (MPLS and Internet) SD-WAN fabric.
Requirements:
- EHR traffic must be in a separate routing domain and completely isolated from other traffic types.
- Guest Wi-Fi traffic from all clinics must be backhauled to the main campus and egress to the internet through a centralized firewall.
- The solution must be scalable and managed centrally from vManage.
Which design approach best satisfies all requirements?
Show answer & explanation
Correct answer: B
This is the ideal solution. Using separate service VPNs (e.g., VPN 10 for EHR, VPN 20 for Guest) provides complete logical isolation with separate routing tables. A centralized control policy can then be applied to the Guest Wi-Fi VPN (VPN 20) to enforce a hub-and-spoke topology, ensuring all its traffic is routed to the main campus for security inspection before egressing to the internet. This meets all stated requirements for segmentation, traffic flow, and compliance.
Ready for the real thing?
The full 300-415 simulator has every exam-style question, timed mode, and instant scoring.