300-415 exam dumps

300-415 practice question 240 of 320

Implementing Cisco SD-WAN Solutions. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-415 Question 240

Select 2

An organization is deploying Cisco SD-WAN to enhance its network security posture. As part of the configuration, they want to enable DNS security to prevent users from accessing malicious domains. Which of the following steps must be performed to implement DNS security in the Cisco SD-WAN solution?

  1. A

    Enable Umbrella integration within the vManage policy framework.

  2. B

    Configure a centralized data policy to redirect DNS traffic to Cisco Umbrella.

  3. C

    Deploy an on-premises DNS server and configure it in the SD-WAN templates.

  4. D

    Enable DNS Security on the vSmart controllers and propagate policies to edge devices.

  5. E

    Ensure the edge devices are configured with a DNS server supporting external domain resolution.

Show answer and explanation

Correct answers: A, B

Explanation

To implement DNS security in Cisco SD-WAN, Umbrella integration must be enabled within the vManage policy framework. Additionally, a centralized data policy is required to redirect DNS traffic to Cisco Umbrella for inspection and filtering. This ensures that malicious domains are blocked and user traffic remains secure. Other options, such as deploying on-premises DNS servers or configuring DNS servers on edge devices, do not achieve the same level of DNS security as Umbrella integration.

  • A. Correct.

    This is correct. Cisco SD-WAN allows integration with Cisco Umbrella for DNS security, which must be enabled within the vManage policy framework.

  • B. Correct.

    This is correct. A centralized data policy is required to redirect DNS traffic to Cisco Umbrella for secure domain resolution.

  • C. Incorrect.

    This is incorrect. While on-premises DNS servers can be used, DNS security in Cisco SD-WAN is typically implemented using Cisco Umbrella integration, not by deploying additional DNS servers.

  • D. Incorrect.

    This is incorrect. DNS security policies are configured and managed within vManage, not directly on the vSmart controllers.

  • E. Incorrect.

    This is incorrect. While DNS servers must be configured on edge devices for domain resolution, this step alone does not implement DNS security.

Timed practice exam

Take a 300-415 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam