300-415 Question 209
Select 3A financial institution is deploying Cisco SD-WAN to improve their WAN connectivity. Due to strict compliance requirements, they need to ensure data confidentiality, integrity, and protection against malware at branch locations. Which Cisco SD-WAN security features should they enable to meet these requirements?
- A
IPSec encryption for data confidentiality
- B
URL filtering to block malicious websites
- C
Next-Generation Firewall (NGFW) for advanced threat protection
- D
Dynamic Multipoint VPN (DMVPN) for secure connectivity
- E
Application-aware routing to optimize user experience
Show answer and explanation
Correct answers: A, B, C
Explanation
To meet the institution's requirements for data confidentiality, integrity, and malware protection, Cisco SD-WAN provides IPSec encryption, URL filtering, and Next-Generation Firewall (NGFW) features. These capabilities ensure secure communication, block malicious websites, and protect against advanced threats. DMVPN and application-aware routing, while useful, do not directly address the stated security needs.
- A. Correct.
IPSec encryption ensures that data transmitted across the WAN is encrypted and secure, meeting the requirement for data confidentiality.
- B. Correct.
URL filtering blocks access to malicious or non-compliant websites, helping to protect against malware and enforce compliance rules.
- C. Correct.
The Next-Generation Firewall (NGFW) provides advanced threat protection by inspecting traffic for malicious activity, meeting the requirement for data integrity and protection.
- D. Incorrect.
DMVPN is not a Cisco SD-WAN security feature; it's a legacy VPN technology. Cisco SD-WAN uses IPSec and secure overlays for connectivity.
- E. Incorrect.
Application-aware routing is a performance optimization feature, not a security feature. It helps optimize user experience but does not address security requirements.