300-415 Question 184
Single answerAn enterprise is deploying Cisco SD-WAN and requires strict separation between their corporate, guest, and IoT traffic. They need to ensure that these traffic types do not interfere with each other while maintaining centralized policy control. Which feature of Cisco SD-WAN should be configured to meet this requirement?
- A
VPN segmentation using different VPN IDs
- B
QoS policies to prioritize traffic
- C
Application-aware routing
- D
Traffic mirroring for monitoring purposes
Show answer and explanation
Correct answer: A
Explanation
VPN segmentation in Cisco SD-WAN is achieved by assigning different VPN IDs to logically separate traffic types such as corporate, guest, and IoT. This ensures that traffic in one VPN does not interfere with traffic in another, meeting the enterprise's requirement for strict traffic separation. Other options like QoS, application-aware routing, and traffic mirroring address different aspects of network performance and monitoring but do not fulfill the need for segmentation.
- A. Correct.
VPN segmentation using different VPN IDs is the correct approach in Cisco SD-WAN to separate traffic into isolated virtual networks. Each VPN ID represents a separate logical network, ensuring strict traffic separation.
- B. Incorrect.
QoS policies are used to manage and prioritize traffic but do not inherently separate traffic types into isolated networks.
- C. Incorrect.
Application-aware routing is used to optimize traffic paths based on application performance, not to isolate traffic into different virtual networks.
- D. Incorrect.
Traffic mirroring is used for monitoring and analysis, not for segmenting or isolating traffic.