300-415 Question 94
Select 2An enterprise is deploying a Cisco SD-WAN solution and wants to ensure secure communications between all network devices. The network administrator is tasked with configuring certificates and device lists to authenticate and onboard devices. Which of the following steps must the administrator perform to successfully onboard devices into the SD-WAN fabric?
- A
Generate Certificate Signing Requests (CSRs) on the vEdge devices and sign them with an Enterprise Root CA.
- B
Manually add the serial numbers of all vEdge devices to the vManage device list.
- C
Ensure that the vManage, vSmart, and vBond controllers have valid certificates signed by a trusted Certificate Authority (CA).
- D
Use the Cisco Plug-and-Play (PnP) portal to automatically register all devices with vManage.
- E
Enable the 'Controller Certificate Authorization' feature on all controllers before onboarding vEdge devices.
Show answer and explanation
Correct answers: B, C
Explanation
To securely onboard devices in a Cisco SD-WAN deployment, the vEdge serial numbers must be added to the vManage device list to establish trust. Additionally, all controller devices (vManage, vSmart, and vBond) must have valid certificates signed by a trusted CA to enable secure communication within the fabric. Other steps, such as manually generating CSRs on vEdge devices or enabling non-existent features, are not required or applicable in this context.
- A. Incorrect.
Incorrect: vEdge certificates are pre-installed or obtained via the Plug-and-Play process. Generating CSRs manually on vEdge devices is not a standard procedure in Cisco SD-WAN.
- B. Correct.
Correct: The serial numbers of vEdge devices must be added to the vManage device list to allow the vManage to authenticate and manage them during onboarding.
- C. Correct.
Correct: All controllers (vManage, vSmart, and vBond) need valid certificates signed by a trusted CA to ensure secure communication within the fabric.
- D. Incorrect.
Incorrect: While the PnP portal can automate certain processes, devices must still be added to the vManage device list to establish trust and communication.
- E. Incorrect.
Incorrect: There is no 'Controller Certificate Authorization' feature in Cisco SD-WAN. Certificates must be installed and validated manually or through an automated process.