300-415 Question 238
Single answerAn organization has deployed Cisco SD-WAN and plans to integrate with a cloud security solution to provide secure internet access for branch sites. They want to ensure that internet-bound traffic is routed through a cloud-based secure web gateway for advanced threat protection and URL filtering. Which Cisco SD-WAN feature should be configured to enable this integration?
- A
Direct Internet Access (DIA)
- B
Cloud OnRamp for SaaS
- C
Secure Internet Gateway (SIG) integration
- D
AppQoE Policies
Show answer and explanation
Correct answer: C
Explanation
The correct option is 'Secure Internet Gateway (SIG) integration' because it directly enables Cisco SD-WAN to route internet-bound traffic through a cloud-based secure web gateway, such as Cisco Umbrella. This provides advanced threat protection, URL filtering, and enhanced security for branch site internet traffic, which aligns with the organization's requirements.
- A. Incorrect.
Direct Internet Access (DIA) allows branch sites to send traffic directly to the internet but does not inherently provide integration with cloud-based security solutions.
- B. Incorrect.
Cloud OnRamp for SaaS optimizes the performance of SaaS applications but does not address routing traffic through a secure web gateway for security purposes.
- C. Correct.
Secure Internet Gateway (SIG) integration is specifically designed to integrate Cisco SD-WAN with cloud-based security solutions, such as Cisco Umbrella, providing advanced threat protection and URL filtering for internet-bound traffic.
- D. Incorrect.
AppQoE Policies are used to optimize application performance by managing quality of experience but do not provide security integration capabilities.