Topic 02 Practice Test 1 covers Catalyst SD-WAN Architecture, Control/Data Planes, Benefits, and Limits for Cisco 350-401 ENCOR. For broader exam preparation, review the Cisco 350-401 ENCOR Exam Dumps. Every option includes focused technical reasoning explaining both the Cisco enterprise networking concept and its fit to the scenario.
Question 1
A cloud engineering team must centralize configuration, monitoring, inventory, and policy administration for the SD-WAN fabric. Which approach most directly satisfies the stated requirement? Choose ONE.
- Catalyst SD-WAN Manager
- application-aware routing policy
- service insertion policy
- underlay reachability prerequisite
Correct Answer(s)
A
Rationale
- Catalyst SD-WAN Manager is correct because it provides the management plane and operational interface for controllers and WAN Edge devices. The stem needs the team to centralize configuration, monitoring, inventory, and policy administration for the SD-WAN fabric. That fit makes Catalyst SD-WAN Manager meet the constraint; alternatives differ materially.
- application-aware routing policy can be appropriate because it combines application classification with path loss, latency, or jitter thresholds. Apply it where voice or transactional traffic should move away from a degraded transport automatically. This case depends on Catalyst SD-WAN Manager, leaving application-aware routing policy mismatched to the requirement.
- The role of service insertion policy is to redirect selected flows through a network service such as a firewall. It is useful when only specified application traffic must traverse a shared inspection service. Here the design needs Catalyst SD-WAN Manager; this choice instead solves an adjacent problem.
- underlay reachability prerequisite can be appropriate because it depends on working IP transport before the overlay can establish control and data tunnels. Apply it where an overlay tunnel cannot form because the underlying circuit has no usable IP path. This case depends on Catalyst SD-WAN Manager, leaving underlay reachability prerequisite mismatched to the requirement.
Question 2
A infrastructure team must distribute overlay routes, TLOC information, and centralized control policy. Which approach most directly satisfies the stated requirement? Choose ONE.
- centralized control policy
- segmentation with VPNs
- Catalyst SD-WAN Controller
- Catalyst SD-WAN Manager
Correct Answer(s)
C
Rationale
- centralized control policy works by distributes policy decisions centrally rather than configuring equivalent route logic on every branch. It fits where many sites require one consistent routing or segmentation policy. The required function here is Catalyst SD-WAN Controller, so this option targets the wrong condition.
- Use segmentation with VPNs to separate routing and policy domains across the SD-WAN overlay. Its mechanism uses service-side VPN segmentation so tenants or business functions remain logically isolated. The current scenario requires Catalyst SD-WAN Controller; segmentation with VPNs solves a different design issue.
- Catalyst SD-WAN Controller is correct because it participates in the control plane and exchanges overlay reachability with WAN Edge routers. The stem needs the team to distribute overlay routes, TLOC information, and centralized control policy. That fit makes Catalyst SD-WAN Controller meet the constraint; alternatives differ materially.
- Catalyst SD-WAN Manager works by provides the management plane and operational interface for controllers and WAN Edge devices. It fits where administrators need centralized lifecycle and policy management rather than packet forwarding. The required function here is Catalyst SD-WAN Controller, so this option targets the wrong condition.
Question 3
A architecture review board must authenticate and help orchestrate initial secure connectivity between fabric components. Which approach most directly satisfies the stated requirement? Choose ONE.
- localized data policy
- control connections over each transport
- Catalyst SD-WAN Validator
- Catalyst SD-WAN Controller
Correct Answer(s)
C
Rationale
- localized data policy can be appropriate because it controls data-plane actions where a branch-specific decision is appropriate. Apply it where one site needs a unique forwarding treatment that should not become fabric-wide policy. This case depends on Catalyst SD-WAN Validator, leaving localized data policy mismatched to the requirement.
- The role of control connections over each transport is to maintain secure controller reachability across available underlay paths. It is useful when a WAN Edge has multiple transports and must retain control-plane resiliency. Here the design needs Catalyst SD-WAN Validator; this choice instead solves an adjacent problem.
- Catalyst SD-WAN Validator is correct because it acts as a trusted orchestration point so authorized components can discover and form control connections. The stem needs the team to authenticate and help orchestrate initial secure connectivity between fabric components. That fit makes Catalyst SD-WAN Validator meet the constraint; alternatives differ materially.
- Catalyst SD-WAN Controller can be appropriate because it participates in the control plane and exchanges overlay reachability with WAN Edge routers. Apply it where the design needs route and policy intelligence without putting user traffic through the controller. This case depends on Catalyst SD-WAN Validator, leaving Catalyst SD-WAN Controller mismatched to the requirement.
Question 4
A production operations group must forward user traffic across secure overlay tunnels according to learned routes and policy. Which approach most directly satisfies the stated requirement? Choose ONE.
- transport independence
- WAN Edge data plane
- zero-touch provisioning
- Catalyst SD-WAN Validator
Correct Answer(s)
B
Rationale
- transport independence is meant to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. Use it when the enterprise wants to mix provider transports without redesigning application addressing. This stem calls for WAN Edge data plane; transport independence addresses another operational need.
- WAN Edge data plane is correct because it terminates transport connections and carries production packets between sites. The stem needs the team to forward user traffic across secure overlay tunnels according to learned routes and policy. That fit makes WAN Edge data plane meet the constraint; alternatives differ materially.
- The role of zero-touch provisioning is to bootstrap new branch devices with minimal local configuration. It is useful when many branches must be deployed without skilled staff entering a full configuration onsite. Here the design needs WAN Edge data plane; this choice instead solves an adjacent problem.
- Use Catalyst SD-WAN Validator to authenticate and help orchestrate initial secure connectivity between fabric components. Its mechanism acts as a trusted orchestration point so authorized components can discover and form control connections. The current scenario requires WAN Edge data plane; Catalyst SD-WAN Validator solves a different design issue.
Question 5
A platform team must advertise overlay prefixes, TLOCs, service routes, and policy attributes through the SD-WAN control plane. Which approach most directly satisfies the stated requirement? Choose ONE.
- OMP route exchange
- IPsec overlay tunnels
- policy-driven path preference
- WAN Edge data plane
Correct Answer(s)
A
Rationale
- OMP route exchange is correct because it uses Overlay Management Protocol to distribute fabric reachability and related attributes. The stem needs the team to advertise overlay prefixes, TLOCs, service routes, and policy attributes through the SD-WAN control plane. That fit makes OMP route exchange meet the constraint; alternatives differ materially.
- IPsec overlay tunnels can be appropriate because it encrypt and authenticate overlay traffic carried over the underlay. Apply it where branch traffic crosses Internet circuits that must not expose cleartext application packets. This case depends on OMP route exchange, leaving IPsec overlay tunnels mismatched to the requirement.
- policy-driven path preference belongs where the business wants deterministic primary/secondary transport behavior beyond pure reachability. It helps to prefer one transport for a traffic class while retaining alternate paths. The stem instead requires OMP route exchange, so policy-driven path preference does not meet the decisive condition.
- WAN Edge data plane belongs where the requirement concerns actual branch-to-branch or branch-to-cloud packet forwarding. It helps to forward user traffic across secure overlay tunnels according to learned routes and policy. The stem instead requires OMP route exchange, so WAN Edge data plane does not meet the decisive condition.
Question 6
A network operations group must represent a WAN Edge transport attachment with attributes used for overlay path selection. Which approach most directly satisfies the stated requirement? Choose ONE.
- TLOC identity
- direct Internet access policy
- controller redundancy
- OMP route exchange
Correct Answer(s)
A
Rationale
- TLOC identity is correct because it identifies transport location characteristics such as system, color, and encapsulation. The stem needs the team to represent a WAN Edge transport attachment with attributes used for overlay path selection. That fit makes TLOC identity meet the constraint; alternatives differ materially.
- direct Internet access policy belongs where SaaS traffic should avoid unnecessary traversal through a central data center. It helps to send approved Internet-bound traffic directly from a branch instead of backhauling it. The stem instead requires TLOC identity, so direct Internet access policy does not meet the decisive condition.
- Use controller redundancy to deploy multiple control and management components to avoid single-controller dependency. Its mechanism uses redundant controllers and resilient control connections so a component failure does not collapse the fabric. The current scenario requires TLOC identity; controller redundancy solves a different design issue.
- OMP route exchange can be appropriate because it uses Overlay Management Protocol to distribute fabric reachability and related attributes. Apply it where WAN Edge routers need overlay reachability without relying on an IGP across every transport. This case depends on TLOC identity, leaving OMP route exchange mismatched to the requirement.
Question 7
A application team must measure liveliness, loss, latency, and jitter across overlay paths. Which approach most directly satisfies the stated requirement? Choose ONE.
- service insertion policy
- BFD tunnel health
- underlay reachability prerequisite
- TLOC identity
Correct Answer(s)
B
Rationale
- The role of service insertion policy is to redirect selected flows through a network service such as a firewall. It is useful when only specified application traffic must traverse a shared inspection service. Here the design needs BFD tunnel health; this choice instead solves an adjacent problem.
- BFD tunnel health is correct because it runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. The stem needs the team to measure liveliness, loss, latency, and jitter across overlay paths. That fit makes BFD tunnel health meet the constraint; alternatives differ materially.
- underlay reachability prerequisite can be appropriate because it depends on working IP transport before the overlay can establish control and data tunnels. Apply it where an overlay tunnel cannot form because the underlying circuit has no usable IP path. This case depends on BFD tunnel health, leaving underlay reachability prerequisite mismatched to the requirement.
- The role of TLOC identity is to represent a WAN Edge transport attachment with attributes used for overlay path selection. It is useful when policy must distinguish multiple underlay transports attached to the same edge. Here the design needs BFD tunnel health; this choice instead solves an adjacent problem.
Question 8
A enterprise architect must steer application traffic according to measured SLA characteristics. Which approach most directly satisfies the stated requirement? Choose ONE.
- segmentation with VPNs
- Catalyst SD-WAN Manager
- application-aware routing policy
- BFD tunnel health
Correct Answer(s)
C
Rationale
- Use segmentation with VPNs to separate routing and policy domains across the SD-WAN overlay. Its mechanism uses service-side VPN segmentation so tenants or business functions remain logically isolated. The current scenario requires application-aware routing policy; segmentation with VPNs solves a different design issue.
- Catalyst SD-WAN Manager works by provides the management plane and operational interface for controllers and WAN Edge devices. It fits where administrators need centralized lifecycle and policy management rather than packet forwarding. The required function here is application-aware routing policy, so this option targets the wrong condition.
- application-aware routing policy is correct because it combines application classification with path loss, latency, or jitter thresholds. The stem needs the team to steer application traffic according to measured SLA characteristics. That fit makes application-aware routing policy meet the constraint; alternatives differ materially.
- BFD tunnel health can be appropriate because it runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. Apply it where application-aware routing needs current path performance evidence. This case depends on application-aware routing policy, leaving BFD tunnel health mismatched to the requirement.
Question 9
A site reliability team must apply fabric-wide route or traffic-policy decisions from controllers. Which approach most directly satisfies the stated requirement? Choose ONE.
- centralized control policy
- control connections over each transport
- Catalyst SD-WAN Controller
- application-aware routing policy
Correct Answer(s)
A
Rationale
- centralized control policy is correct because it distributes policy decisions centrally rather than configuring equivalent route logic on every branch. The stem needs the team to apply fabric-wide route or traffic-policy decisions from controllers. That fit makes centralized control policy meet the constraint; alternatives differ materially.
- The role of control connections over each transport is to maintain secure controller reachability across available underlay paths. It is useful when a WAN Edge has multiple transports and must retain control-plane resiliency. Here the design needs centralized control policy; this choice instead solves an adjacent problem.
- Catalyst SD-WAN Controller can be appropriate because it participates in the control plane and exchanges overlay reachability with WAN Edge routers. Apply it where the design needs route and policy intelligence without putting user traffic through the controller. This case depends on centralized control policy, leaving Catalyst SD-WAN Controller mismatched to the requirement.
- application-aware routing policy belongs where voice or transactional traffic should move away from a degraded transport automatically. It helps to steer application traffic according to measured SLA characteristics. The stem instead requires centralized control policy, so application-aware routing policy does not meet the decisive condition.
Question 10
A security engineering group must apply a policy at a specific WAN Edge for local forwarding behavior. Which approach most directly satisfies the stated requirement? Choose ONE.
- zero-touch provisioning
- Catalyst SD-WAN Validator
- localized data policy
- centralized control policy
Correct Answer(s)
C
Rationale
- The role of zero-touch provisioning is to bootstrap new branch devices with minimal local configuration. It is useful when many branches must be deployed without skilled staff entering a full configuration onsite. Here the design needs localized data policy; this choice instead solves an adjacent problem.
- Use Catalyst SD-WAN Validator to authenticate and help orchestrate initial secure connectivity between fabric components. Its mechanism acts as a trusted orchestration point so authorized components can discover and form control connections. The current scenario requires localized data policy; Catalyst SD-WAN Validator solves a different design issue.
- localized data policy is correct because it controls data-plane actions where a branch-specific decision is appropriate. The stem needs the team to apply a policy at a specific WAN Edge for local forwarding behavior. That fit makes localized data policy meet the constraint; alternatives differ materially.
- centralized control policy can be appropriate because it distributes policy decisions centrally rather than configuring equivalent route logic on every branch. Apply it where many sites require one consistent routing or segmentation policy. This case depends on localized data policy, leaving centralized control policy mismatched to the requirement.
Question 11
A branch deployment team must build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. Which approach most directly satisfies the stated requirement? Choose ONE.
- policy-driven path preference
- transport independence
- WAN Edge data plane
- localized data policy
Correct Answer(s)
B
Rationale
- policy-driven path preference belongs where the business wants deterministic primary/secondary transport behavior beyond pure reachability. It helps to prefer one transport for a traffic class while retaining alternate paths. The stem instead requires transport independence, so policy-driven path preference does not meet the decisive condition.
- transport independence is correct because it abstracts service reachability from individual transport technologies while secure tunnels span them. The stem needs the team to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. That fit makes transport independence meet the constraint; alternatives differ materially.
- WAN Edge data plane belongs where the requirement concerns actual branch-to-branch or branch-to-cloud packet forwarding. It helps to forward user traffic across secure overlay tunnels according to learned routes and policy. The stem instead requires transport independence, so WAN Edge data plane does not meet the decisive condition.
- localized data policy belongs where one site needs a unique forwarding treatment that should not become fabric-wide policy. It helps to apply a policy at a specific WAN Edge for local forwarding behavior. The stem instead requires transport independence, so localized data policy does not meet the decisive condition.
Question 12
A support organization must protect data-plane traffic between WAN Edge devices across untrusted transports. Which approach most directly satisfies the stated requirement? Choose ONE.
- controller redundancy
- OMP route exchange
- transport independence
- IPsec overlay tunnels
Correct Answer(s)
D
Rationale
- Use controller redundancy to deploy multiple control and management components to avoid single-controller dependency. Its mechanism uses redundant controllers and resilient control connections so a component failure does not collapse the fabric. The current scenario requires IPsec overlay tunnels; controller redundancy solves a different design issue.
- OMP route exchange can be appropriate because it uses Overlay Management Protocol to distribute fabric reachability and related attributes. Apply it where WAN Edge routers need overlay reachability without relying on an IGP across every transport. This case depends on IPsec overlay tunnels, leaving OMP route exchange mismatched to the requirement.
- The role of transport independence is to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. It is useful when the enterprise wants to mix provider transports without redesigning application addressing. Here the design needs IPsec overlay tunnels; this choice instead solves an adjacent problem.
- IPsec overlay tunnels is correct because it encrypt and authenticate overlay traffic carried over the underlay. The stem needs the team to protect data-plane traffic between WAN Edge devices across untrusted transports. That fit makes IPsec overlay tunnels meet the constraint; alternatives differ materially.
Question 13
A cloud engineering team must send approved Internet-bound traffic directly from a branch instead of backhauling it. Which approach most directly satisfies the stated requirement? Choose ONE.
- underlay reachability prerequisite
- TLOC identity
- direct Internet access policy
- IPsec overlay tunnels
Correct Answer(s)
C
Rationale
- underlay reachability prerequisite can be appropriate because it depends on working IP transport before the overlay can establish control and data tunnels. Apply it where an overlay tunnel cannot form because the underlying circuit has no usable IP path. This case depends on direct Internet access policy, leaving underlay reachability prerequisite mismatched to the requirement.
- The role of TLOC identity is to represent a WAN Edge transport attachment with attributes used for overlay path selection. It is useful when policy must distinguish multiple underlay transports attached to the same edge. Here the design needs direct Internet access policy; this choice instead solves an adjacent problem.
- direct Internet access policy is correct because it uses local breakout with security and policy controls to shorten the path to Internet services. The stem needs the team to send approved Internet-bound traffic directly from a branch instead of backhauling it. That fit makes direct Internet access policy meet the constraint; alternatives differ materially.
- IPsec overlay tunnels belongs where branch traffic crosses Internet circuits that must not expose cleartext application packets. It helps to protect data-plane traffic between WAN Edge devices across untrusted transports. The stem instead requires direct Internet access policy, so IPsec overlay tunnels does not meet the decisive condition.
Question 14
A infrastructure team must redirect selected flows through a network service such as a firewall. Which approach most directly satisfies the stated requirement? Choose ONE.
- service insertion policy
- Catalyst SD-WAN Manager
- BFD tunnel health
- direct Internet access policy
Correct Answer(s)
A
Rationale
- service insertion policy is correct because it steers traffic through an approved service path according to centralized policy. The stem needs the team to redirect selected flows through a network service such as a firewall. That fit makes service insertion policy meet the constraint; alternatives differ materially.
- Catalyst SD-WAN Manager works by provides the management plane and operational interface for controllers and WAN Edge devices. It fits where administrators need centralized lifecycle and policy management rather than packet forwarding. The required function here is service insertion policy, so this option targets the wrong condition.
- BFD tunnel health can be appropriate because it runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. Apply it where application-aware routing needs current path performance evidence. This case depends on service insertion policy, leaving BFD tunnel health mismatched to the requirement.
- direct Internet access policy works by uses local breakout with security and policy controls to shorten the path to Internet services. It fits where SaaS traffic should avoid unnecessary traversal through a central data center. The required function here is service insertion policy, so this option targets the wrong condition.
Question 15
A architecture review board must separate routing and policy domains across the SD-WAN overlay. Which approach most directly satisfies the stated requirement? Choose ONE.
- Catalyst SD-WAN Controller
- segmentation with VPNs
- application-aware routing policy
- service insertion policy
Correct Answer(s)
B
Rationale
- Catalyst SD-WAN Controller can be appropriate because it participates in the control plane and exchanges overlay reachability with WAN Edge routers. Apply it where the design needs route and policy intelligence without putting user traffic through the controller. This case depends on segmentation with VPNs, leaving Catalyst SD-WAN Controller mismatched to the requirement.
- segmentation with VPNs is correct because it uses service-side VPN segmentation so tenants or business functions remain logically isolated. The stem needs the team to separate routing and policy domains across the SD-WAN overlay. That fit makes segmentation with VPNs meet the constraint; alternatives differ materially.
- application-aware routing policy belongs where voice or transactional traffic should move away from a degraded transport automatically. It helps to steer application traffic according to measured SLA characteristics. The stem instead requires segmentation with VPNs, so application-aware routing policy does not meet the decisive condition.
- Use service insertion policy to redirect selected flows through a network service such as a firewall. Its mechanism steers traffic through an approved service path according to centralized policy. The current scenario requires segmentation with VPNs; service insertion policy solves a different design issue.
Question 16
A production operations group must maintain secure controller reachability across available underlay paths. Which approach most directly satisfies the stated requirement? Choose ONE.
- Catalyst SD-WAN Validator
- centralized control policy
- segmentation with VPNs
- control connections over each transport
Correct Answer(s)
D
Rationale
- Use Catalyst SD-WAN Validator to authenticate and help orchestrate initial secure connectivity between fabric components. Its mechanism acts as a trusted orchestration point so authorized components can discover and form control connections. The current scenario requires control connections over each transport; Catalyst SD-WAN Validator solves a different design issue.
- centralized control policy can be appropriate because it distributes policy decisions centrally rather than configuring equivalent route logic on every branch. Apply it where many sites require one consistent routing or segmentation policy. This case depends on control connections over each transport, leaving centralized control policy mismatched to the requirement.
- segmentation with VPNs is meant to separate routing and policy domains across the SD-WAN overlay. Use it when multiple business groups share the same WAN Edge infrastructure but require separate routing domains. This stem calls for control connections over each transport; segmentation with VPNs addresses another operational need.
- control connections over each transport is correct because it forms authenticated control sessions that allow the edge to participate in the fabric even when transports change. The stem needs the team to maintain secure controller reachability across available underlay paths. That fit makes control connections over each transport meet the constraint; alternatives differ materially.
Question 17
A platform team must bootstrap new branch devices with minimal local configuration. Which approach most directly satisfies the stated requirement? Choose ONE.
- WAN Edge data plane
- localized data policy
- control connections over each transport
- zero-touch provisioning
Correct Answer(s)
D
Rationale
- WAN Edge data plane belongs where the requirement concerns actual branch-to-branch or branch-to-cloud packet forwarding. It helps to forward user traffic across secure overlay tunnels according to learned routes and policy. The stem instead requires zero-touch provisioning, so WAN Edge data plane does not meet the decisive condition.
- localized data policy belongs where one site needs a unique forwarding treatment that should not become fabric-wide policy. It helps to apply a policy at a specific WAN Edge for local forwarding behavior. The stem instead requires zero-touch provisioning, so localized data policy does not meet the decisive condition.
- Use control connections over each transport to maintain secure controller reachability across available underlay paths. Its mechanism forms authenticated control sessions that allow the edge to participate in the fabric even when transports change. The current scenario requires zero-touch provisioning; control connections over each transport solves a different design issue.
- zero-touch provisioning is correct because it uses orchestrated discovery and secure onboarding to apply intended software and configuration. The stem needs the team to bootstrap new branch devices with minimal local configuration. That fit makes zero-touch provisioning meet the constraint; alternatives differ materially.
Question 18
A network operations group must prefer one transport for a traffic class while retaining alternate paths. Which approach most directly satisfies the stated requirement? Choose ONE.
- OMP route exchange
- policy-driven path preference
- transport independence
- zero-touch provisioning
Correct Answer(s)
B
Rationale
- OMP route exchange can be appropriate because it uses Overlay Management Protocol to distribute fabric reachability and related attributes. Apply it where WAN Edge routers need overlay reachability without relying on an IGP across every transport. This case depends on policy-driven path preference, leaving OMP route exchange mismatched to the requirement.
- policy-driven path preference is correct because it uses centralized route or traffic policy attributes to influence selected TLOCs. The stem needs the team to prefer one transport for a traffic class while retaining alternate paths. That fit makes policy-driven path preference meet the constraint; alternatives differ materially.
- The role of transport independence is to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. It is useful when the enterprise wants to mix provider transports without redesigning application addressing. Here the design needs policy-driven path preference; this choice instead solves an adjacent problem.
- Use zero-touch provisioning to bootstrap new branch devices with minimal local configuration. Its mechanism uses orchestrated discovery and secure onboarding to apply intended software and configuration. The current scenario requires policy-driven path preference; zero-touch provisioning solves a different design issue.
Question 19
A application team must deploy multiple control and management components to avoid single-controller dependency. Which approach most directly satisfies the stated requirement? Choose ONE.
- TLOC identity
- IPsec overlay tunnels
- policy-driven path preference
- controller redundancy
Correct Answer(s)
D
Rationale
- The role of TLOC identity is to represent a WAN Edge transport attachment with attributes used for overlay path selection. It is useful when policy must distinguish multiple underlay transports attached to the same edge. Here the design needs controller redundancy; this choice instead solves an adjacent problem.
- IPsec overlay tunnels belongs where branch traffic crosses Internet circuits that must not expose cleartext application packets. It helps to protect data-plane traffic between WAN Edge devices across untrusted transports. The stem instead requires controller redundancy, so IPsec overlay tunnels does not meet the decisive condition.
- policy-driven path preference works by uses centralized route or traffic policy attributes to influence selected TLOCs. It fits where the business wants deterministic primary/secondary transport behavior beyond pure reachability. The required function here is controller redundancy, so this option targets the wrong condition.
- controller redundancy is correct because it uses redundant controllers and resilient control connections so a component failure does not collapse the fabric. The stem needs the team to deploy multiple control and management components to avoid single-controller dependency. That fit makes controller redundancy meet the constraint; alternatives differ materially.
Question 20
A enterprise architect must ensure each WAN Edge transport can reach required controller and peer destinations. Which approach most directly satisfies the stated requirement? Choose ONE.
- BFD tunnel health
- direct Internet access policy
- controller redundancy
- underlay reachability prerequisite
Correct Answer(s)
D
Rationale
- BFD tunnel health can be appropriate because it runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. Apply it where application-aware routing needs current path performance evidence. This case depends on underlay reachability prerequisite, leaving BFD tunnel health mismatched to the requirement.
- direct Internet access policy works by uses local breakout with security and policy controls to shorten the path to Internet services. It fits where SaaS traffic should avoid unnecessary traversal through a central data center. The required function here is underlay reachability prerequisite, so this option targets the wrong condition.
- controller redundancy is meant to deploy multiple control and management components to avoid single-controller dependency. Use it when the design must tolerate loss of an individual controller instance. This stem calls for underlay reachability prerequisite; controller redundancy addresses another operational need.
- underlay reachability prerequisite is correct because it depends on working IP transport before the overlay can establish control and data tunnels. The stem needs the team to ensure each WAN Edge transport can reach required controller and peer destinations. That fit makes underlay reachability prerequisite meet the constraint; alternatives differ materially.