300-415 Question 217
Select 3You have deployed Cisco SD-WAN in your organization, and you are tasked with enabling Intrusion Prevention System (IPS) to enhance security. Which steps must you complete to successfully configure IPS within the Cisco SD-WAN solution?
- A
Enable the IPS feature in the security policy and associate it with the appropriate VPN.
- B
Ensure the vSmart controller is configured as the IPS enforcement point.
- C
Download and activate the latest Snort signatures on the vEdge devices.
- D
Enable application-aware routing to detect IPS-relevant traffic patterns.
- E
Apply the IPS configuration through a centralized policy on vManage.
Show answer and explanation
Correct answers: A, C, E
Explanation
To configure IPS in Cisco SD-WAN, the IPS feature must be enabled in the security policy and associated with the relevant VPNs. Additionally, the latest Snort signatures must be downloaded and activated on edge devices to ensure they are equipped to detect and prevent threats. Finally, the configuration is applied through centralized policies in vManage to enforce the IPS settings across the network. vSmart controllers do not act as IPS enforcement points, and application-aware routing is unrelated to IPS.
- A. Correct.
Correct: IPS must be enabled in the security policy, and it needs to be associated with the VPNs where the protection is required.
- B. Incorrect.
Incorrect: The vSmart controller does not act as an IPS enforcement point; IPS is enforced at the edge devices such as vEdge or cEdge.
- C. Correct.
Correct: Cisco SD-WAN uses Snort for IPS, and the latest signatures must be downloaded and activated on the edge devices to ensure up-to-date protection.
- D. Incorrect.
Incorrect: Application-aware routing is not related to IPS functionality; it is used for traffic steering based on application performance and SLA metrics.
- E. Correct.
Correct: The IPS configuration is applied via centralized policies through vManage, which allows for streamlined deployment across the network.