Designing and Implementing Cloud Connectivity — Free Practice Questions
10 free sample questions from a bank of 18, with the correct answers and explanations. No signup required — start practising right now.
1A company with multiple branch offices wants a connectivity model to meet its network architecture requirements. The company focuses on ensuring low latency and efficient routing for its critical business applications. Which connectivity model meets these requirements?
hub-and-spoke topology with SD-WAN technology, using dynamic routing and OSPF as the routing protocol
fully meshed topology with SD-WAN technology, using dynamic routing and BGP as the routing protocol
point-to-point topology using dedicated leased lines and static routing
star topology with internet-based VPN connections and static routing
Answer: B
The short version
B — Fully meshed SD-WAN with BGP is the low-latency choice. A full mesh lets branch sites exchange critical traffic directly instead of hairpinning through a hub, and BGP handles the larger dynamic policy set.
Key concepts in this question
SD-WAN topology: hub-and-spoke backhauls traffic; full mesh enables direct spoke-to-spoke paths.
Dynamic routing: path selection reacts to SLA, loss, and latency rather than fixed static next hops.
BGP in SD-WAN: preferred for large, policy-rich overlays; OSPF fits smaller single-domain underlays.
Why B is correct
A fully meshed SD-WAN overlay builds direct tunnels between branches, so critical applications take the shortest available path with the lowest latency. Dynamic routing continuously steers around brownouts, and BGP scales better than OSPF for multi-site policy, filtering, and cloud/on-premises redistribution.
Why the others are wrong
A. Hub-and-spoke forces inter-branch traffic through the hub, adding latency and a bottleneck — the opposite of the requirement.
C. Point-to-point leased lines with static routing are rigid, expensive to mesh, and do not adapt to latency changes.
D. Star VPN with static routing still hairpins through the center and cannot do SLA-based dynamic path selection.
300-440 exam tip
Think mesh equals direct and low-latency, hub-and-spoke equals centralized and higher latency; pair mesh questions with BGP scale.
2Refer to the exhibits. An engineer must redistribute OSPF internal routes into BGP to connect an on-premises network to a cloud provider. Which two commands should the engineer run on router R2? (Choose two.)
router bgp 100
redistribute bgp 100
router ospf 1
redistribute ospf 1
redistribute ospf 100
Answer: A, D
The short version
A and D — Enter BGP 100, then redistribute OSPF 1 into it. That pair puts the engineer in the right BGP process and injects the on-premises OSPF routes toward the cloud provider.
Key concepts in this question
Redistribution direction: the source protocol is named under the receiving protocol.
Process IDs: OSPF 1 and BGP 100 are separate; the numbers must match the running processes.
Router context: redistribution commands only take effect inside the destination routing process.
Why A and D are correct
To move OSPF internal routes into BGP on R2, the engineer must first enter router bgp 100 and then issue redistribute ospf 1 from that BGP context. This imports the OSPF-learned prefixes into the BGP table for advertisement to the cloud edge, which is the stated direction.
Why the others are wrong
B.redistribute bgp 100 is the reverse direction and would inject BGP into something else, not OSPF into BGP.
C.router ospf 1 enters the wrong process; anything configured there cannot inject routes into BGP.
E.redistribute ospf 100 names a nonexistent OSPF process 100 instead of the running OSPF 1, so nothing would be redistributed.
300-440 exam tip
Read redistribution backwards from the goal: destination process first, then redistribute source; match the exact process numbers shown.
3Refer to the exhibits.While troubleshooting, a network engineer discovers that the backup path fails between ASBR3 and ASBR4 for traffic between BGP AS6000 and BGP AS6500 when the connection between ASBR1 and ASBR2 goes down. The following configurations were performed on ASBR1:Which command is missing?
bgp additional-paths Install
bgp additional-paths select
redistribute static
bgp advertise-best-external
Answer: D
The short version
D — Advertise the best external path so the backup survives. Without bgp advertise-best-external, only the best overall path is shared and the alternate ASBR-to-ASBR backup disappears when the primary link fails.
Key concepts in this question
BGP best-path: by default only the single best path is advertised to peers.
Best-external: advertises the best external path in addition to the best path for fast failover.
ASBR redundancy: ASBR1/ASBR2 and ASBR3/ASBR4 must each have a usable path to both autonomous systems.
Why D is correct
When ASBR1–ASBR2 is up, ASBR1 picks one best path and hides the external alternate learned from its eBGP peer. If that link drops, ASBR3/ASBR4 have no backup because they never received it. bgp advertise-best-external forces advertisement of the best external route alongside the best route, preserving the ASBR3–ASBR4 backup between AS6000 and AS6500.
Why the others are wrong
A.bgp additional-paths install installs backup paths locally in the RIB but does not advertise the external backup to peers.
B.bgp additional-paths select only selects which additional paths are candidates; alone it does not advertise best-external.
C.redistribute static injects static routes and has no role in preserving alternate eBGP paths.
300-440 exam tip
Backup-path-between-ASBRs failing after primary loss equals missing best-external; additional-paths is about multiple paths locally, not the external backup advertisement.
4Refer to the exhibit. These configurations are complete: Create an account in the Equinix portal. Associate the Equinix account with Cisco vManage.* Configure the global settings for Interconnect Gateways.Drag the prerequisite steps from the left onto the order on the right to configure a Cisco SD-WAN Cloud Interconnect with Equinix
Answer:
The short version
The correct order runs create Equinix account then associate the account then configure global settings then attach the template then create the gateway. The reconstructed exhibit lists the first three items as already complete and asks for the prerequisite order that builds the Cloud Interconnect gateway.
Key concepts in this question
Cloud Interconnect depends on identity before defaults before placement. The Equinix portal account with client credentials and billing must exist first so SD-WAN Manager has something to associate and the global settings then supply the reusable gateway defaults that the template attachment and gateway creation consume.
Why this order is correct
Each step supplies the object the next step consumes. The account creates the Equinix identity and billing scope and the association imports that identity into SD-WAN Manager and the global settings define the image and sizing defaults and the template attachment binds a real Catalyst 8000v instance and only then can the gateway be created at the closest metro so any earlier creation or later association leaves a dangling reference.
Why the others are wrong
Any reorder breaks the dependency chain. Creating the gateway before the account or before the association points at no provider identity and configuring global settings before the association saves defaults with no account context and attaching the template before global settings binds an instance with no agreed image or size so only the stated sequence provisions cleanly.
300-440 exam tip
Remember Equinix order as account plus associate plus global settings plus attach template plus create gateway.
5What is the role of service providers to establish private connectivity between on-premises networks and Google Cloud resources?
facilitate direct, dedicated network connections through Google Cloud Interconnect
enable intelligent routing and dynamic path selection using software-defined networking
provide end-to-end encryption for data transmission using native IPsec
accelerate content delivery through integration with Google Cloud CDN
Answer: A
The short version
A — Providers deliver private access through Google Cloud Interconnect. The provider provisions a direct, dedicated circuit rather than sending traffic over the public internet.
Key concepts in this question
Cloud Interconnect: dedicated or partner attachment from on-premises to Google Cloud edge.
Service-provider role: last-mile and metro transport plus the Interconnect attachment, not cloud routing logic.
Private connectivity: stays off the internet, with consistent latency and SLA.
Why A is correct
Google Cloud Interconnect is the private on-ramp: Dedicated Interconnect or Partner Interconnect carried by a provider gives a direct VLAN attachment into the customer VPC. The provider's job is to facilitate that dedicated connection, which is exactly what private on-premises-to-Google connectivity requires.
Why the others are wrong
B. Intelligent routing and dynamic path selection describe SD-WAN behavior, not the provider's Interconnect transport role.
C. End-to-end IPsec encryption is a customer VPN design choice, not the defining function of Interconnect private circuits.
D. CDN integration accelerates public content delivery and is unrelated to private VPC connectivity.
300-440 exam tip
Interconnect always means private dedicated pipe; if the stem says private on-premises to cloud, pick the dedicated-connection answer over VPN, SDN, or CDN.
6Drag and drop the commands from the left onto the purposes on the right to identify issues on a Cisco IOS XE SD-WAN device.
Answer:
Answer
Correct mapping — MATCH
Control connections → vSmart/vBond; BFD → data-plane; OMP peers → routes; System status → health.
Why this mapping is correct
IOS XE SD-WAN triage flow
Control connections prove orchestration reachability, BFD proves tunnel liveness, OMP peers prove route exchange, and system status proves device health; policy show is the distractor.
300-440 exam tip
SD-WAN show pattern
Remember: control is vSmart/vBond, BFD is data-plane, OMP is routes, system is health.
7Refer to the exhibit.A network engineer discovers that the policy that is configured on an on-premises Cisco WAN edge router affects only the route tables of the specific devices that are listed in the site list. What is the problem?
An inbound policy must be applied.
The action must be set to deny
A localized data policy must be configured.
A centralized data policy must be configured
Answer: D
The short version
D — A site-wide effect needs a centralized data policy. A policy touching only listed devices' route tables is acting locally, so the engineer must move the intent to vManage centralized data policy.
Key concepts in this question
Centralized data policy: pushed from vManage/vSmart to affect forwarding across sites.
Localized data policy: applied on the device and affects only that device's tables.
Control vs data policy: control affects routing advertisements; data affects forwarding paths.
Why D is correct
The symptom is scope: only the explicitly listed devices change, which is localized behavior. To enforce the same forwarding outcome across the WAN edge consistently, the engineer configures a centralized data policy in vManage so the controller programs all in-scope sites, not just the box where the CLI was entered.
Why the others are wrong
A. An inbound direction change does not widen scope from local to centralized; it only changes match direction.
B. Setting action to deny changes permit/deny outcome, not whether the policy is local or centralized.
C. A localized data policy is the cause of the narrow effect, so adding more localization keeps the same problem.
300-440 exam tip
Only-listed-devices affected equals localized; cross-site intent equals centralized data policy pushed from vManage.
8Refer to the exhibits. An engineer must redistribute only the 10.0.10.0/24 network into BGP to connect an on-premises network to a public cloud provider. These routes are currently redistributed:Which command is missing on router R2?
neighbor 10.0.10.2 remote-as 100
redistribute ospf 1 match internal
redistribute ospf 1 match external
neighbor 10.0.10.0/24 remote-as 100
Answer: C
The short version
C — The wanted prefix is external, so match external. OSPF redistribution into BGP defaults to internal routes, which filters out the external 10.0.10.0/24 until match external is added.
Key concepts in this question
OSPF route types: internal covers intra- and inter-area; external covers Type-1 and Type-2 redistributed routes.
Redistribution default: OSPF-to-BGP without a match keyword only takes internal routes.
Selective advertisement: match external narrows the injection to the external prefix needed for the cloud.
Why C is correct
The target 10.0.10.0/24 exists in OSPF as an external route, so plain redistribute ospf 1 will not pick it up for BGP. Adding redistribute ospf 1 match external on R2 explicitly imports external OSPF routes, letting only that external network enter BGP toward the public cloud provider.
Why the others are wrong
A.neighbor 10.0.10.2 remote-as 100 defines a BGP peering, not which OSPF type enters BGP.
B.redistribute ospf 1 match internal does the opposite: it keeps internal routes and continues to exclude the external target.
D.neighbor 10.0.10.0/24 remote-as 100 is invalid syntax; a neighbor must be a single IP, not a prefix, and it still would not filter by route type.
300-440 exam tip
External prefix missing from BGP after OSPF redistribution means add match external; internal-only is the IOS default trap.
9An engineer must enable the OMP advertisement of BGP routes for a specific VRF instance on a Cisco IOS XE SD-WAN device. What should be configured after the global address-family ipv4 is configured?
Set the VRF-specific route advertisements.
Enable bgp advertisement.
Enter sdwan mode.
Disable bgp advertisement.
Answer: B
The short version
B — Turn on BGP advertisement so OMP can carry the VRF routes. After the global IPv4 address family, enabling BGP advertisement lets the edge redistribute BGP-learned VRF prefixes into OMP.
Key concepts in this question
OMP: SD-WAN overlay protocol that carries site routes between edges via the controller.
VRF route flow: service-side BGP must be advertised into OMP per VRF.
IOS XE SD-WAN order: global address family first, then per-VRF advertisement toggle.
Why B is correct
By default the VRF BGP routes stay local to the device. Once address-family ipv4 is configured globally, bgp advertisement enables redistribution of those BGP routes into OMP for that VRF, so remote edges learn them over the overlay. That is the documented next step for this use case.
Why the others are wrong
A. Setting VRF-specific advertisements is too vague and skips the actual enable knob the platform requires.
C. Entering SD-WAN mode is a mode prerequisite, not the post-address-family step that turns on advertisement.
D. Disabling BGP advertisement does the reverse and would keep the VRF routes out of OMP.
300-440 exam tip
VRF BGP into OMP needs the advertisement switch on; after address-family, look for enable bgp advertisement, not disable or a mode change.
10Refer to the exhibit.A company uses Cisco SD-WAN in the data center. All devices have the default configuration. An engineer attempts to add a new centralized control policy in Cisco vManage but receives an error message. What is the problem?
A centralized control policy is already applied to the specific site ID and direction
The policy for "Hub" should be applied in the outbound direction, and the policy for "All-Site" should be applied inbound.
Apply an additional outbound control policy to override the site ID overlaps.
Site-list "All-Site" should be configured with a new match sequence that is lower than the sequence for site-list "Hub*.
Answer: D
The short version
D — Overlapping site-lists collide, so resequence All-Site below Hub. Centralized control policy evaluates sequences in order, and the broader list must come after the specific Hub exception.
Key concepts in this question
Site-lists: Hub is the specific exception; All-Site is the catch-all.
Sequence numbers: lower numbers match first in vManage policy.
Overlap error: two applied policies covering the same site and direction are rejected.
Why D is correct
With default configuration, adding a new centralized control policy that overlaps the existing Hub and All-Site coverage triggers a site-ID/direction conflict. Giving All-Site a lower-priority sequence number than Hub orders the matches so Hub exceptions apply first and the general policy follows, clearing the vManage error.
Why the others are wrong
A. An already-applied policy in the same direction is the symptom, not the fix; the fix is ordering, not merely noting the collision.
B. Swapping inbound/outbound directions does not resolve overlapping site coverage in the same direction.
C. Stacking another outbound policy on top of the overlap compounds the conflict instead of sequencing it correctly.
300-440 exam tip
vManage overlap error with Hub plus All-Site means check sequence order: specific Hub first, general All-Site after.