Implementing Cisco SD-WAN Solutions (ENSDWI 300-415) — Free Practice Questions
10 free sample questions from a bank of 572, with the correct answers and explanations. No signup required — start practising right now.
1What are three types of data that JSON uses when Cisco APIC REST API uses JavaScript?
SCALAR, POST, and OBJECT
SCALAR, OBJECT, and ARRAY
GET, PUT, and DELETE
GET, PUT, and POST
Answer: B
The short version
B — JSON values fall into scalar, object, and array types. Cisco API payloads parse into these three shapes, while GET, PUT, POST, and DELETE are HTTP methods used to move the payloads, not data types.
Key concepts in this question
Scalar: single values such as strings, numbers, booleans, and null.
Object: unordered key-value map, the basis of most REST bodies.
Array: ordered list of values or objects.
HTTP methods vs data: verbs like GET and POST act on data; they do not classify it.
Why B is correct
JSON only needs three structural categories: scalars for leaf values, objects for named fields, and arrays for lists. A Cisco APIC REST body is therefore some nesting of these three, and JavaScript parses them natively into primitives, objects, and arrays, so B describes the data model exactly.
Why the others are wrong
A. POST is an HTTP method, not a JSON data type, so the set is mixed and invalid.
C. GET, PUT, and DELETE are all request verbs; none is a JSON type.
D. Same flaw as C: these name operations on resources, not value structures.
300-415 exam tip
When options mix HTTP verbs with data types, verbs answer how it moves and types answer how it is shaped — pick the shape answer.
2How does Cisco Umbrella respond to the client if the FQDN in the DNS query is one of the grey- listed domains?
It returns the IP address of the content provider.
It returns the unicast IP addresses of intelligent proxy.
It returns the IP address of the blocked landing page.
No response is sent: traffic is blocked.
Answer: B
The short version
B — Greylisted domains resolve to the intelligent proxy. Umbrella returns the proxy's unicast IPs so the session can be inspected and filtered inline instead of going straight to the content provider.
Key concepts in this question
Greylisting: domain is suspicious but not confirmed malicious, so access is brokered.
Intelligent proxy: cloud proxy that fetches, inspects, and filters risky URLs and files.
DNS-layer enforcement: the verdict is delivered by steering resolution, not by dropping packets silently.
Why B is correct
For a grey domain Umbrella must neither allow it directly nor hard-block it. Returning the intelligent proxy addresses forces the client's web session through the proxy, which then allows benign content and blocks only the malicious objects — exactly the greylist behavior in B.
Why the others are wrong
A. The provider's real IP would bypass inspection, defeating the purpose of greylisting.
C. The blocked landing-page IP is the response for denied (blacklisted) categories, not grey ones.
D. Silent drops describe hard blocks or failures; greylisted users get a proxied, working session.
300-415 exam tip
Grey means proxy, black means block page: if the domain is only suspicious, Umbrella steers it to the intelligent proxy.
3Refer to the exhibit. Which policy configuration applies to site 101 without affecting the overlay network?
apply-policysite-list SiteAcontrol-policy Path-Pref in
apply-policysite-list SiteBcontrol-policy Path-Pref out
apply-policysite-list SiteBcontrol-policy Path-Pref in
apply-policysite-list SiteAcontrol-policy Path-Pref out
Answer: A
The short version
A — approved. The site 101 requirement is met by applying the Path-Pref control policy inbound to SiteA. Exhibit missing; reconstructed exhibit is described below.
Key concepts in this question
The stem is: Refer to the exhibit. Which policy configuration applies to site 101 without affecting the overlay network. Options are A. apply-policy site-list SiteA control-policy Path-Pref in, B. apply-policy site-list SiteB control-policy Path-Pref out, C. apply-policy site-list SiteB control-policy Path-Pref in, D. apply-policy site-list SiteA control-policy Path-Pref out. The reconstructed exhibit consistent with the stem and banked answer is a vSmart policy where SiteA contains site 101, SiteB contains other sites, and Path-Pref is a control policy whose inbound application only affects routes presented to SiteA without changing overlay-wide advertisements.
Why A is correct
A targets site-list SiteA, which holds site 101, in the inbound direction, so only site 101 ingress route handling is changed and the rest of the overlay is unaffected.
Why the others are wrong
B targets SiteB, so it misses site 101 entirely. C targets SiteB, so it also misses site 101 even though the direction is inbound. D targets the right site-list SiteA but in the outbound direction, which changes what is advertised outward and affects the overlay beyond site 101.
300-415 exam tip
Match the site-list to the required site ID first, then use in versus out to limit overlay impact.
4Which storage format is used when vManage is deployed as a virtual machine on a KVM hypervisor?
.iso
.tgz
.ova
.qcow2
Answer: D
The short version
D — KVM deployments use the .qcow2 disk image. QCOW2 is the native QEMU/KVM copy-on-write disk format, while the other extensions belong to different hypervisors or media.
Key concepts in this question
qcow2: KVM/QEMU disk image with snapshots and thin provisioning.
OVA: OVF package typically used for VMware/ESXi and similar hypervisors.
ISO/TGZ: bootable media and compressed archives, not KVM virtual disks.
Why D is correct
vManage on KVM runs as a QEMU guest, whose virtual disks use the qcow2 format with copy-on-write, snapshots, and sparse allocation. Cisco therefore ships the KVM variant as a .qcow2 image, making D the only format the KVM hypervisor consumes directly.
Why the others are wrong
A. .iso is installation or boot media, not a provisioned virtual disk.
B. .tgz is a compressed tarball for packaging files, not a bootable disk image.
C. .ova targets OVF-based hypervisors such as ESXi, not KVM.
300-415 exam tip
Match the extension to the hypervisor: qcow2 goes with KVM, OVA with ESXi, ISO with bare installs.
5Refer to the exhibit. A vBond controller was added to the controller list with the same Enterprise Root CA certificate as vManage. The two controllers can reach each other via VPNO and share the same organization name, but the control connection is not initiated. Which action resolves the issue?
Configure NTP on both controllers to establish a connection.
Synchronize the WAN Edge list on vManage with controllers.
Configure a valid system IP on the vBond controller.
Configure a valid vBond IP on vManage.
Answer: D
The short version
D — vManage needs the vBond address configured to build control connections. Controllers discover and authenticate each other through vBond, so without its peer address vManage never initiates the DTLS/TLS session even when reachability, CA, and organization name match.
Key concepts in this question
vBond orchestrator: first contact that introduces controllers and edges into the overlay.
Control connections: DTLS/TLS sessions between controllers carrying management and routing state.
Peer configuration: each controller must be told its vBond address explicitly.
Why D is correct
Matching certificates, organization name, and VPN 0 reachability only prove the controllers could talk; vManage still needs to know where vBond is. Configuring the valid vBond IP on vManage gives it the destination for the control connection, after which authentication and session setup proceed, so D resolves the stuck state.
Why the others are wrong
A. NTP skew breaks certificate validation, but nothing here indicates clock or certificate errors.
B. Syncing the WAN Edge list affects edge onboarding, not controller-to-controller adjacency.
C. A valid system IP on vBond is required anyway, yet it cannot substitute for the peer address configured on vManage.
300-415 exam tip
Controllers reachable but not connecting means check the configured peers first: vManage must point at vBond.
6Drag and Drop QuestionDrag and drop the steps from the left into the order on the right to delete a software image for a WAN Edge router starting with Maintenance > Software Upgrade > Device list on vManage.
Answer:
The short version
MATCH — Approved: vManage image-delete navigation and removal mapping. Starting from Maintenance > Software Upgrade > Device list, select the WAN Edge version, delete it, then verify removal.
Key concepts in this question
vManage software upgrade workflow: Maintenance > Software Upgrade > Device list is the entry point.
WAN Edge image selection: target the correct device and unused version before deletion.
Delete and verify: confirm removal and check storage is freed.
Why this mapping is correct
Each left step maps to its purpose on the right: navigation reaches software management, selection targets the correct device/version, delete executes removal, and verification confirms success. Cisco documents image deletion from the Device list with version selection, delete confirmation, and verification of available storage.
300-415 exam tip
If the stem starts with Maintenance > Software Upgrade > Device list, the first step is navigation, then select device/version, then delete/confirm, then verify.
7For data plane resiliency, what does the Cisco SD-WAN software implement?
BFD
establishing affinity between vSmart controllers and WAN Edge routers
multiple vBond orchestrators
OMP
Answer: A
The short version
A — Data-plane resiliency rides on BFD. BFD sessions over the IPsec tunnels detect path failure in milliseconds and trigger fast reroute, which is the SD-WAN data-plane liveness mechanism.
Key concepts in this question
BFD: lightweight hello protocol for sub-second failure detection.
Data plane vs control plane: tunnel forwarding health versus OMP route exchange.
Resiliency: detect a dead path and move flows before users notice.
Why A is correct
SD-WAN edges run BFD over each tunnel to continuously measure liveness, loss, latency, and jitter. When probes fail, the edge immediately steers traffic to a healthy tunnel without waiting for routing-protocol timers, which is precisely data-plane resiliency, so A is correct.
Why the others are wrong
B. vSmart-to-edge affinity is a control-plane scaling choice, not forwarding failure detection.
C. Extra vBonds harden device onboarding, not the fate of user traffic on tunnels.
D. OMP distributes routes in the control plane; it does not probe data-path liveness.
300-415 exam tip
BFD watches the path, OMP spreads the routes: data-plane failure questions want BFD.
8Which two architectural components are part of an SD-WAN high availability vManage cluster?(Choose two.)
network configuration system
WAN Edge router
NAT router
messaging server
application server
Answer: A, E
The short version
AE — Messaging server and application server are vManage cluster components. They are core NMS services distributed across cluster nodes for scale and HA.
Key concepts in this question
vManage/SD-WAN Manager cluster: up to 64 nodes sharing application, messaging, config and statistics services.
Application server: hosts the NMS application logic and GUI/API.
Messaging server: handles inter-node messaging and coordination.
Why AE is correct
Cisco documents the cluster as a set of NMS services including the application server and the messaging server (alongside configuration and statistics databases). WAN Edge routers and NAT routers are data-plane/transport elements, not cluster members.
Why the others are wrong
B. WAN Edge router is a data-plane device, not a manager-cluster service.
C. NAT router is a transport function, unrelated to the NMS cluster.
300-415 exam tip
Memorize the four NMS services: app server, config DB, stats DB, messaging server — exam distractors add routers.
9Which secure connection should be used to access the REST APIs through the Cisco vManage web server?
HTTP inspector interface
authenticated HTTPS
authenticated DTLS
JSON Inspector interface
Answer: B
The short version
B — vManage REST APIs are reached over authenticated HTTPS. The web server fronts the API with TLS encryption plus login credentials or tokens, unlike the overlay's DTLS or plain HTTP.
Key concepts in this question
REST over TLS: API calls ride HTTPS to the vManage web server.
Authentication: session login or token authorizes each API consumer.
DTLS role: secures overlay control and data tunnels, not browser or API access.
Why B is correct
Clients automate vManage through its northbound REST endpoints, which the embedded web server exposes as HTTPS URLs. TLS gives confidentiality and integrity while authentication proves who the caller is, so authenticated HTTPS in B is exactly the supported secure access method.
Why the others are wrong
A. There is no HTTP inspector interface for API access, and plain HTTP would lack encryption.
C. Authenticated DTLS protects edge-to-controller tunnels, not REST calls to the web server.
D. A JSON inspector is a debugging and viewing aid, not an access protocol.
300-415 exam tip
API calls to the manager go over HTTPS; DTLS belongs to the overlay tunnels.
10Which policy tracks path characteristics such as loss, latency, and jitter in vManage?
VPN
control
app-route
data
Answer: C
The short version
C — Loss, latency, and jitter are tracked by the app-route policy. App-aware routing measures SLA per tunnel with BFD and application probes and steers each application onto compliant paths.
Key concepts in this question
App-route policy: SLA classes plus preferred and backup colors per application.
SLA probes: BFD measurements of loss, latency, and jitter per tunnel.
Control, data, VPN policies: topology control, forwarding actions, and attachment — none of which grade path SLA.
Why C is correct
Only app-route policy consumes the per-tunnel SLA telemetry and acts on it: when a path violates the configured loss, latency, or jitter thresholds, the edge reroutes the application's flows to a compliant tunnel. That closed loop of measurement plus steering is the behavior the question describes, so C is correct.
Why the others are wrong
A. A VPN policy defines segmentation and attachment, not path quality.
B. Control policy shapes OMP topology and route advertisement, not SLA steering.
D. Data policy sets forwarding, NAT, and firewalling actions rather than SLA measurement.
300-415 exam tip
See loss, latency, and jitter together and think app-route: it is the only policy that grades paths by SLA.