Topic 02 Practice Test 2 covers Catalyst SD-WAN Architecture, Control/Data Planes, Benefits, and Limits for Cisco 350-401 ENCOR. For broader exam preparation, review the Cisco 350-401 ENCOR Exam Dumps. Every option includes focused technical reasoning explaining both the Cisco enterprise networking concept and its fit to the scenario.
Question 1
Administrators need centralized lifecycle and policy management rather than packet forwarding, but the current design is not providing the expected result. The network operations group wants a component that provides the management plane and operational interface for controllers and WAN Edge devices. Which change should be made? Choose ONE.
- Catalyst SD-WAN Manager
- transport independence
- controller redundancy
- BFD tunnel health
Correct Answer(s)
A
Rationale
- Choose Catalyst SD-WAN Manager. Its function is to provides the management plane and operational interface for controllers and WAN Edge devices. Here the required outcome is to centralize configuration, monitoring, inventory, and policy administration for the SD-WAN fabric. This capability places Catalyst SD-WAN Manager at the proper layer; alternatives do not.
- Use transport independence to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. Its mechanism abstracts service reachability from individual transport technologies while secure tunnels span them. The current scenario requires Catalyst SD-WAN Manager; transport independence solves a different design issue.
- controller redundancy is meant to deploy multiple control and management components to avoid single-controller dependency. Use it when the design must tolerate loss of an individual controller instance. This stem calls for Catalyst SD-WAN Manager; controller redundancy addresses another operational need.
- BFD tunnel health can be appropriate because it runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. Apply it where application-aware routing needs current path performance evidence. This case depends on Catalyst SD-WAN Manager, leaving BFD tunnel health mismatched to the requirement.
Question 2
The design needs route and policy intelligence without putting user traffic through the controller, but the current design is not providing the expected result. The application team wants a component that participates in the control plane and exchanges overlay reachability with WAN Edge routers. Which change should be made? Choose ONE.
- IPsec overlay tunnels
- underlay reachability prerequisite
- Catalyst SD-WAN Controller
- application-aware routing policy
Correct Answer(s)
C
Rationale
- IPsec overlay tunnels works by encrypt and authenticate overlay traffic carried over the underlay. It fits where branch traffic crosses Internet circuits that must not expose cleartext application packets. The required function here is Catalyst SD-WAN Controller, so this option targets the wrong condition.
- underlay reachability prerequisite belongs where an overlay tunnel cannot form because the underlying circuit has no usable IP path. It helps to ensure each WAN Edge transport can reach required controller and peer destinations. The stem instead requires Catalyst SD-WAN Controller, so underlay reachability prerequisite does not meet the decisive condition.
- Choose Catalyst SD-WAN Controller. Its function is to participates in the control plane and exchanges overlay reachability with WAN Edge routers. Here the required outcome is to distribute overlay routes, TLOC information, and centralized control policy. This capability places Catalyst SD-WAN Controller at the proper layer; alternatives do not.
- application-aware routing policy belongs where voice or transactional traffic should move away from a degraded transport automatically. It helps to steer application traffic according to measured SLA characteristics. The stem instead requires Catalyst SD-WAN Controller, so application-aware routing policy does not meet the decisive condition.
Question 3
New devices must securely bootstrap into the fabric before normal control sessions form, but the current design is not providing the expected result. The enterprise architect wants a component that acts as a trusted orchestration point so authorized components can discover and form control connections. Which change should be made? Choose ONE.
- direct Internet access policy
- Catalyst SD-WAN Manager
- centralized control policy
- Catalyst SD-WAN Validator
Correct Answer(s)
D
Rationale
- direct Internet access policy can be appropriate because it uses local breakout with security and policy controls to shorten the path to Internet services. Apply it where SaaS traffic should avoid unnecessary traversal through a central data center. This case depends on Catalyst SD-WAN Validator, leaving direct Internet access policy mismatched to the requirement.
- Catalyst SD-WAN Manager can be appropriate because it provides the management plane and operational interface for controllers and WAN Edge devices. Apply it where administrators need centralized lifecycle and policy management rather than packet forwarding. This case depends on Catalyst SD-WAN Validator, leaving Catalyst SD-WAN Manager mismatched to the requirement.
- centralized control policy can be appropriate because it distributes policy decisions centrally rather than configuring equivalent route logic on every branch. Apply it where many sites require one consistent routing or segmentation policy. This case depends on Catalyst SD-WAN Validator, leaving centralized control policy mismatched to the requirement.
- Choose Catalyst SD-WAN Validator. Its function is to acts as a trusted orchestration point so authorized components can discover and form control connections. Here the required outcome is to authenticate and help orchestrate initial secure connectivity between fabric components. This capability places Catalyst SD-WAN Validator at the proper layer; alternatives do not.
Question 4
The requirement concerns actual branch-to-branch or branch-to-cloud packet forwarding, but the current design is not providing the expected result. The site reliability team wants a component that terminates transport connections and carries production packets between sites. Which change should be made? Choose ONE.
- service insertion policy
- WAN Edge data plane
- Catalyst SD-WAN Controller
- localized data policy
Correct Answer(s)
B
Rationale
- service insertion policy is meant to redirect selected flows through a network service such as a firewall. Use it when only specified application traffic must traverse a shared inspection service. This stem calls for WAN Edge data plane; service insertion policy addresses another operational need.
- Choose WAN Edge data plane. Its function is to terminates transport connections and carries production packets between sites. Here the required outcome is to forward user traffic across secure overlay tunnels according to learned routes and policy. This capability places WAN Edge data plane at the proper layer; alternatives do not.
- Catalyst SD-WAN Controller belongs where the design needs route and policy intelligence without putting user traffic through the controller. It helps to distribute overlay routes, TLOC information, and centralized control policy. The stem instead requires WAN Edge data plane, so Catalyst SD-WAN Controller does not meet the decisive condition.
- localized data policy belongs where one site needs a unique forwarding treatment that should not become fabric-wide policy. It helps to apply a policy at a specific WAN Edge for local forwarding behavior. The stem instead requires WAN Edge data plane, so localized data policy does not meet the decisive condition.
Question 5
Wan edge routers need overlay reachability without relying on an igp across every transport, but the current design is not providing the expected result. The security engineering group wants a component that uses Overlay Management Protocol to distribute fabric reachability and related attributes. Which change should be made? Choose ONE.
- OMP route exchange
- segmentation with VPNs
- Catalyst SD-WAN Validator
- transport independence
Correct Answer(s)
A
Rationale
- Choose OMP route exchange. Its function is to uses Overlay Management Protocol to distribute fabric reachability and related attributes. Here the required outcome is to advertise overlay prefixes, TLOCs, service routes, and policy attributes through the SD-WAN control plane. This capability places OMP route exchange at the proper layer; alternatives do not.
- The role of segmentation with VPNs is to separate routing and policy domains across the SD-WAN overlay. It is useful when multiple business groups share the same WAN Edge infrastructure but require separate routing domains. Here the design needs OMP route exchange; this choice instead solves an adjacent problem.
- Catalyst SD-WAN Validator is meant to authenticate and help orchestrate initial secure connectivity between fabric components. Use it when new devices must securely bootstrap into the fabric before normal control sessions form. This stem calls for OMP route exchange; Catalyst SD-WAN Validator addresses another operational need.
- The role of transport independence is to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. It is useful when the enterprise wants to mix provider transports without redesigning application addressing. Here the design needs OMP route exchange; this choice instead solves an adjacent problem.
Question 6
Policy must distinguish multiple underlay transports attached to the same edge, but the current design is not providing the expected result. The branch deployment team wants a component that identifies transport location characteristics such as system, color, and encapsulation. Which change should be made? Choose ONE.
- control connections over each transport
- WAN Edge data plane
- IPsec overlay tunnels
- TLOC identity
Correct Answer(s)
D
Rationale
- control connections over each transport is meant to maintain secure controller reachability across available underlay paths. Use it when a WAN Edge has multiple transports and must retain control-plane resiliency. This stem calls for TLOC identity; control connections over each transport addresses another operational need.
- WAN Edge data plane works by terminates transport connections and carries production packets between sites. It fits where the requirement concerns actual branch-to-branch or branch-to-cloud packet forwarding. The required function here is TLOC identity, so this option targets the wrong condition.
- IPsec overlay tunnels belongs where branch traffic crosses Internet circuits that must not expose cleartext application packets. It helps to protect data-plane traffic between WAN Edge devices across untrusted transports. The stem instead requires TLOC identity, so IPsec overlay tunnels does not meet the decisive condition.
- Choose TLOC identity. Its function is to identifies transport location characteristics such as system, color, and encapsulation. Here the required outcome is to represent a WAN Edge transport attachment with attributes used for overlay path selection. This capability places TLOC identity at the proper layer; alternatives do not.
Question 7
Application-aware routing needs current path performance evidence, but the current design is not providing the expected result. The support organization wants a component that runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. Which change should be made? Choose ONE.
- zero-touch provisioning
- OMP route exchange
- direct Internet access policy
- BFD tunnel health
Correct Answer(s)
D
Rationale
- zero-touch provisioning is meant to bootstrap new branch devices with minimal local configuration. Use it when many branches must be deployed without skilled staff entering a full configuration onsite. This stem calls for BFD tunnel health; zero-touch provisioning addresses another operational need.
- OMP route exchange belongs where WAN Edge routers need overlay reachability without relying on an IGP across every transport. It helps to advertise overlay prefixes, TLOCs, service routes, and policy attributes through the SD-WAN control plane. The stem instead requires BFD tunnel health, so OMP route exchange does not meet the decisive condition.
- direct Internet access policy works by uses local breakout with security and policy controls to shorten the path to Internet services. It fits where SaaS traffic should avoid unnecessary traversal through a central data center. The required function here is BFD tunnel health, so this option targets the wrong condition.
- Choose BFD tunnel health. Its function is to runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. Here the required outcome is to measure liveliness, loss, latency, and jitter across overlay paths. This capability places BFD tunnel health at the proper layer; alternatives do not.
Question 8
Voice or transactional traffic should move away from a degraded transport automatically, but the current design is not providing the expected result. The cloud engineering team wants a component that combines application classification with path loss, latency, or jitter thresholds. Which change should be made? Choose ONE.
- policy-driven path preference
- application-aware routing policy
- TLOC identity
- service insertion policy
Correct Answer(s)
B
Rationale
- policy-driven path preference can be appropriate because it uses centralized route or traffic policy attributes to influence selected TLOCs. Apply it where the business wants deterministic primary/secondary transport behavior beyond pure reachability. This case depends on application-aware routing policy, leaving policy-driven path preference mismatched to the requirement.
- Choose application-aware routing policy. Its function is to combines application classification with path loss, latency, or jitter thresholds. Here the required outcome is to steer application traffic according to measured SLA characteristics. This capability places application-aware routing policy at the proper layer; alternatives do not.
- Use TLOC identity to represent a WAN Edge transport attachment with attributes used for overlay path selection. Its mechanism identifies transport location characteristics such as system, color, and encapsulation. The current scenario requires application-aware routing policy; TLOC identity solves a different design issue.
- Use service insertion policy to redirect selected flows through a network service such as a firewall. Its mechanism steers traffic through an approved service path according to centralized policy. The current scenario requires application-aware routing policy; service insertion policy solves a different design issue.
Question 9
Many sites require one consistent routing or segmentation policy, but the current design is not providing the expected result. The infrastructure team wants a component that distributes policy decisions centrally rather than configuring equivalent route logic on every branch. Which change should be made? Choose ONE.
- controller redundancy
- centralized control policy
- BFD tunnel health
- segmentation with VPNs
Correct Answer(s)
B
Rationale
- The role of controller redundancy is to deploy multiple control and management components to avoid single-controller dependency. It is useful when the design must tolerate loss of an individual controller instance. Here the design needs centralized control policy; this choice instead solves an adjacent problem.
- Choose centralized control policy. Its function is to distributes policy decisions centrally rather than configuring equivalent route logic on every branch. Here the required outcome is to apply fabric-wide route or traffic-policy decisions from controllers. This capability places centralized control policy at the proper layer; alternatives do not.
- BFD tunnel health belongs where application-aware routing needs current path performance evidence. It helps to measure liveliness, loss, latency, and jitter across overlay paths. The stem instead requires centralized control policy, so BFD tunnel health does not meet the decisive condition.
- segmentation with VPNs is meant to separate routing and policy domains across the SD-WAN overlay. Use it when multiple business groups share the same WAN Edge infrastructure but require separate routing domains. This stem calls for centralized control policy; segmentation with VPNs addresses another operational need.
Question 10
One site needs a unique forwarding treatment that should not become fabric-wide policy, but the current design is not providing the expected result. The architecture review board wants a component that controls data-plane actions where a branch-specific decision is appropriate. Which change should be made? Choose ONE.
- underlay reachability prerequisite
- application-aware routing policy
- control connections over each transport
- localized data policy
Correct Answer(s)
D
Rationale
- underlay reachability prerequisite works by depends on working IP transport before the overlay can establish control and data tunnels. It fits where an overlay tunnel cannot form because the underlying circuit has no usable IP path. The required function here is localized data policy, so this option targets the wrong condition.
- application-aware routing policy works by combines application classification with path loss, latency, or jitter thresholds. It fits where voice or transactional traffic should move away from a degraded transport automatically. The required function here is localized data policy, so this option targets the wrong condition.
- Use control connections over each transport to maintain secure controller reachability across available underlay paths. Its mechanism forms authenticated control sessions that allow the edge to participate in the fabric even when transports change. The current scenario requires localized data policy; control connections over each transport solves a different design issue.
- Choose localized data policy. Its function is to controls data-plane actions where a branch-specific decision is appropriate. Here the required outcome is to apply a policy at a specific WAN Edge for local forwarding behavior. This capability places localized data policy at the proper layer; alternatives do not.
Question 11
The enterprise wants to mix provider transports without redesigning application addressing, but the current design is not providing the expected result. The production operations group wants a component that abstracts service reachability from individual transport technologies while secure tunnels span them. Which change should be made? Choose ONE.
- transport independence
- Catalyst SD-WAN Manager
- centralized control policy
- zero-touch provisioning
Correct Answer(s)
A
Rationale
- Choose transport independence. Its function is to abstracts service reachability from individual transport technologies while secure tunnels span them. Here the required outcome is to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. This capability places transport independence at the proper layer; alternatives do not.
- Catalyst SD-WAN Manager belongs where administrators need centralized lifecycle and policy management rather than packet forwarding. It helps to centralize configuration, monitoring, inventory, and policy administration for the SD-WAN fabric. The stem instead requires transport independence, so Catalyst SD-WAN Manager does not meet the decisive condition.
- centralized control policy belongs where many sites require one consistent routing or segmentation policy. It helps to apply fabric-wide route or traffic-policy decisions from controllers. The stem instead requires transport independence, so centralized control policy does not meet the decisive condition.
- Use zero-touch provisioning to bootstrap new branch devices with minimal local configuration. Its mechanism uses orchestrated discovery and secure onboarding to apply intended software and configuration. The current scenario requires transport independence; zero-touch provisioning solves a different design issue.
Question 12
Branch traffic crosses internet circuits that must not expose cleartext application packets, but the current design is not providing the expected result. The platform team wants a component that encrypt and authenticate overlay traffic carried over the underlay. Which change should be made? Choose ONE.
- IPsec overlay tunnels
- Catalyst SD-WAN Controller
- localized data policy
- policy-driven path preference
Correct Answer(s)
A
Rationale
- Choose IPsec overlay tunnels. Its function is to encrypt and authenticate overlay traffic carried over the underlay. Here the required outcome is to protect data-plane traffic between WAN Edge devices across untrusted transports. This capability places IPsec overlay tunnels at the proper layer; alternatives do not.
- Catalyst SD-WAN Controller works by participates in the control plane and exchanges overlay reachability with WAN Edge routers. It fits where the design needs route and policy intelligence without putting user traffic through the controller. The required function here is IPsec overlay tunnels, so this option targets the wrong condition.
- localized data policy works by controls data-plane actions where a branch-specific decision is appropriate. It fits where one site needs a unique forwarding treatment that should not become fabric-wide policy. The required function here is IPsec overlay tunnels, so this option targets the wrong condition.
- policy-driven path preference works by uses centralized route or traffic policy attributes to influence selected TLOCs. It fits where the business wants deterministic primary/secondary transport behavior beyond pure reachability. The required function here is IPsec overlay tunnels, so this option targets the wrong condition.
Question 13
Saas traffic should avoid unnecessary traversal through a central data center, but the current design is not providing the expected result. The network operations group wants a component that uses local breakout with security and policy controls to shorten the path to Internet services. Which change should be made? Choose ONE.
- Catalyst SD-WAN Validator
- transport independence
- direct Internet access policy
- controller redundancy
Correct Answer(s)
C
Rationale
- The role of Catalyst SD-WAN Validator is to authenticate and help orchestrate initial secure connectivity between fabric components. It is useful when new devices must securely bootstrap into the fabric before normal control sessions form. Here the design needs direct Internet access policy; this choice instead solves an adjacent problem.
- Use transport independence to build the overlay across heterogeneous underlays such as MPLS, broadband, or cellular. Its mechanism abstracts service reachability from individual transport technologies while secure tunnels span them. The current scenario requires direct Internet access policy; transport independence solves a different design issue.
- Choose direct Internet access policy. Its function is to uses local breakout with security and policy controls to shorten the path to Internet services. Here the required outcome is to send approved Internet-bound traffic directly from a branch instead of backhauling it. This capability places direct Internet access policy at the proper layer; alternatives do not.
- controller redundancy is meant to deploy multiple control and management components to avoid single-controller dependency. Use it when the design must tolerate loss of an individual controller instance. This stem calls for direct Internet access policy; controller redundancy addresses another operational need.
Question 14
Only specified application traffic must traverse a shared inspection service, but the current design is not providing the expected result. The application team wants a component that steers traffic through an approved service path according to centralized policy. Which change should be made? Choose ONE.
- WAN Edge data plane
- service insertion policy
- IPsec overlay tunnels
- underlay reachability prerequisite
Correct Answer(s)
B
Rationale
- WAN Edge data plane can be appropriate because it terminates transport connections and carries production packets between sites. Apply it where the requirement concerns actual branch-to-branch or branch-to-cloud packet forwarding. This case depends on service insertion policy, leaving WAN Edge data plane mismatched to the requirement.
- Choose service insertion policy. Its function is to steers traffic through an approved service path according to centralized policy. Here the required outcome is to redirect selected flows through a network service such as a firewall. This capability places service insertion policy at the proper layer; alternatives do not.
- IPsec overlay tunnels works by encrypt and authenticate overlay traffic carried over the underlay. It fits where branch traffic crosses Internet circuits that must not expose cleartext application packets. The required function here is service insertion policy, so this option targets the wrong condition.
- underlay reachability prerequisite belongs where an overlay tunnel cannot form because the underlying circuit has no usable IP path. It helps to ensure each WAN Edge transport can reach required controller and peer destinations. The stem instead requires service insertion policy, so underlay reachability prerequisite does not meet the decisive condition.
Question 15
Multiple business groups share the same wan edge infrastructure but require separate routing domains, but the current design is not providing the expected result. The enterprise architect wants a component that uses service-side VPN segmentation so tenants or business functions remain logically isolated. Which change should be made? Choose ONE.
- OMP route exchange
- direct Internet access policy
- segmentation with VPNs
- Catalyst SD-WAN Manager
Correct Answer(s)
C
Rationale
- OMP route exchange works by uses Overlay Management Protocol to distribute fabric reachability and related attributes. It fits where WAN Edge routers need overlay reachability without relying on an IGP across every transport. The required function here is segmentation with VPNs, so this option targets the wrong condition.
- direct Internet access policy can be appropriate because it uses local breakout with security and policy controls to shorten the path to Internet services. Apply it where SaaS traffic should avoid unnecessary traversal through a central data center. This case depends on segmentation with VPNs, leaving direct Internet access policy mismatched to the requirement.
- Choose segmentation with VPNs. Its function is to uses service-side VPN segmentation so tenants or business functions remain logically isolated. Here the required outcome is to separate routing and policy domains across the SD-WAN overlay. This capability places segmentation with VPNs at the proper layer; alternatives do not.
- Catalyst SD-WAN Manager can be appropriate because it provides the management plane and operational interface for controllers and WAN Edge devices. Apply it where administrators need centralized lifecycle and policy management rather than packet forwarding. This case depends on segmentation with VPNs, leaving Catalyst SD-WAN Manager mismatched to the requirement.
Question 16
A wan edge has multiple transports and must retain control-plane resiliency, but the current design is not providing the expected result. The site reliability team wants a component that forms authenticated control sessions that allow the edge to participate in the fabric even when transports change. Which change should be made? Choose ONE.
- TLOC identity
- service insertion policy
- control connections over each transport
- Catalyst SD-WAN Controller
Correct Answer(s)
C
Rationale
- TLOC identity is meant to represent a WAN Edge transport attachment with attributes used for overlay path selection. Use it when policy must distinguish multiple underlay transports attached to the same edge. This stem calls for control connections over each transport; TLOC identity addresses another operational need.
- service insertion policy is meant to redirect selected flows through a network service such as a firewall. Use it when only specified application traffic must traverse a shared inspection service. This stem calls for control connections over each transport; service insertion policy addresses another operational need.
- Choose control connections over each transport. Its function is to forms authenticated control sessions that allow the edge to participate in the fabric even when transports change. Here the required outcome is to maintain secure controller reachability across available underlay paths. This capability places control connections over each transport at the proper layer; alternatives do not.
- Catalyst SD-WAN Controller belongs where the design needs route and policy intelligence without putting user traffic through the controller. It helps to distribute overlay routes, TLOC information, and centralized control policy. The stem instead requires control connections over each transport, so Catalyst SD-WAN Controller does not meet the decisive condition.
Question 17
Many branches must be deployed without skilled staff entering a full configuration onsite, but the current design is not providing the expected result. The security engineering group wants a component that uses orchestrated discovery and secure onboarding to apply intended software and configuration. Which change should be made? Choose ONE.
- BFD tunnel health
- zero-touch provisioning
- segmentation with VPNs
- Catalyst SD-WAN Validator
Correct Answer(s)
B
Rationale
- BFD tunnel health works by runs sessions between WAN Edge devices so path quality and reachability can be evaluated rapidly. It fits where application-aware routing needs current path performance evidence. The required function here is zero-touch provisioning, so this option targets the wrong condition.
- Choose zero-touch provisioning. Its function is to uses orchestrated discovery and secure onboarding to apply intended software and configuration. Here the required outcome is to bootstrap new branch devices with minimal local configuration. This capability places zero-touch provisioning at the proper layer; alternatives do not.
- The role of segmentation with VPNs is to separate routing and policy domains across the SD-WAN overlay. It is useful when multiple business groups share the same WAN Edge infrastructure but require separate routing domains. Here the design needs zero-touch provisioning; this choice instead solves an adjacent problem.
- Catalyst SD-WAN Validator is meant to authenticate and help orchestrate initial secure connectivity between fabric components. Use it when new devices must securely bootstrap into the fabric before normal control sessions form. This stem calls for zero-touch provisioning; Catalyst SD-WAN Validator addresses another operational need.
Question 18
The business wants deterministic primary/secondary transport behavior beyond pure reachability, but the current design is not providing the expected result. The branch deployment team wants a component that uses centralized route or traffic policy attributes to influence selected TLOCs. Which change should be made? Choose ONE.
- application-aware routing policy
- control connections over each transport
- policy-driven path preference
- WAN Edge data plane
Correct Answer(s)
C
Rationale
- application-aware routing policy can be appropriate because it combines application classification with path loss, latency, or jitter thresholds. Apply it where voice or transactional traffic should move away from a degraded transport automatically. This case depends on policy-driven path preference, leaving application-aware routing policy mismatched to the requirement.
- control connections over each transport is meant to maintain secure controller reachability across available underlay paths. Use it when a WAN Edge has multiple transports and must retain control-plane resiliency. This stem calls for policy-driven path preference; control connections over each transport addresses another operational need.
- Choose policy-driven path preference. Its function is to uses centralized route or traffic policy attributes to influence selected TLOCs. Here the required outcome is to prefer one transport for a traffic class while retaining alternate paths. This capability places policy-driven path preference at the proper layer; alternatives do not.
- WAN Edge data plane works by terminates transport connections and carries production packets between sites. It fits where the requirement concerns actual branch-to-branch or branch-to-cloud packet forwarding. The required function here is policy-driven path preference, so this option targets the wrong condition.
Question 19
The design must tolerate loss of an individual controller instance, but the current design is not providing the expected result. The support organization wants a component that uses redundant controllers and resilient control connections so a component failure does not collapse the fabric. Which change should be made? Choose ONE.
- centralized control policy
- zero-touch provisioning
- OMP route exchange
- controller redundancy
Correct Answer(s)
D
Rationale
- centralized control policy works by distributes policy decisions centrally rather than configuring equivalent route logic on every branch. It fits where many sites require one consistent routing or segmentation policy. The required function here is controller redundancy, so this option targets the wrong condition.
- zero-touch provisioning is meant to bootstrap new branch devices with minimal local configuration. Use it when many branches must be deployed without skilled staff entering a full configuration onsite. This stem calls for controller redundancy; zero-touch provisioning addresses another operational need.
- OMP route exchange belongs where WAN Edge routers need overlay reachability without relying on an IGP across every transport. It helps to advertise overlay prefixes, TLOCs, service routes, and policy attributes through the SD-WAN control plane. The stem instead requires controller redundancy, so OMP route exchange does not meet the decisive condition.
- Choose controller redundancy. Its function is to uses redundant controllers and resilient control connections so a component failure does not collapse the fabric. Here the required outcome is to deploy multiple control and management components to avoid single-controller dependency. This capability places controller redundancy at the proper layer; alternatives do not.
Question 20
An overlay tunnel cannot form because the underlying circuit has no usable ip path, but the current design is not providing the expected result. The cloud engineering team wants a component that depends on working IP transport before the overlay can establish control and data tunnels. Which change should be made? Choose ONE.
- underlay reachability prerequisite
- localized data policy
- policy-driven path preference
- TLOC identity
Correct Answer(s)
A
Rationale
- Choose underlay reachability prerequisite. Its function is to depends on working IP transport before the overlay can establish control and data tunnels. Here the required outcome is to ensure each WAN Edge transport can reach required controller and peer destinations. This capability places underlay reachability prerequisite at the proper layer; alternatives do not.
- localized data policy can be appropriate because it controls data-plane actions where a branch-specific decision is appropriate. Apply it where one site needs a unique forwarding treatment that should not become fabric-wide policy. This case depends on underlay reachability prerequisite, leaving localized data policy mismatched to the requirement.
- policy-driven path preference can be appropriate because it uses centralized route or traffic policy attributes to influence selected TLOCs. Apply it where the business wants deterministic primary/secondary transport behavior beyond pure reachability. This case depends on underlay reachability prerequisite, leaving policy-driven path preference mismatched to the requirement.
- Use TLOC identity to represent a WAN Edge transport attachment with attributes used for overlay path selection. Its mechanism identifies transport location characteristics such as system, color, and encapsulation. The current scenario requires underlay reachability prerequisite; TLOC identity solves a different design issue.