300-415 exam dumps

300-415 practice question 187 of 320

Implementing Cisco SD-WAN Solutions. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-415 Question 187

Single answer

An enterprise uses Cisco SD-WAN to segment its network into multiple VPNs for different business units. The IT team needs to ensure that traffic from the Sales department (VPN 10) cannot communicate with the Finance department (VPN 20). However, both departments should still have access to shared services hosted in VPN 30. What is the best way to achieve this requirement?

  1. A

    Configure access control lists (ACLs) to block communication between VPN 10 and VPN 20 while allowing both to communicate with VPN 30.

  2. B

    Use centralized control policies to block inter-VPN traffic between VPN 10 and VPN 20, and allow shared service access to VPN 30.

  3. C

    Implement localized data policies on each router to deny traffic between VPN 10 and VPN 20.

  4. D

    Use a single VPN for all departments and rely on firewall rules to restrict traffic as needed.

Show answer and explanation

Correct answer: B

Explanation

Centralized control policies in Cisco SD-WAN enable administrators to define consistent and scalable inter-VPN segmentation rules from the controller. This ensures that different VPNs, such as VPN 10 and VPN 20, remain isolated while allowing shared access to specific VPNs like VPN 30 for shared services. This approach aligns with SD-WAN best practices for segmentation and traffic management.

  • A. Incorrect.

    While ACLs could potentially block unwanted communication, they are not the most efficient solution in an SD-WAN environment for inter-VPN segmentation. Centralized control policies are more scalable and aligned with the SD-WAN architecture.

  • B. Correct.

    Centralized control policies are the optimal solution for segmenting VPNs in Cisco SD-WAN. They allow you to define traffic policies at the control plane, ensuring that VPN 10 and VPN 20 cannot communicate while enabling access to VPN 30. This approach is scalable and consistent.

  • C. Incorrect.

    Localized data policies operate at the edge router level and are not suitable for managing inter-VPN segmentation across the entire SD-WAN fabric.

  • D. Incorrect.

    Using a single VPN for all departments would completely eliminate segmentation, defeating the purpose of using VPNs for isolating traffic between business units. This approach is not recommended.

Timed practice exam

Take a 300-415 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam