Skip to content

300-415 Implementing Cisco Catalyst SD-WAN Solutions (ENSDWI) Practice Questions

Prepare for 300-415 with more than an answer.

177 questions in the full set20 sample questionsUpdated Aug 20, 2026
Exam fee
$300 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 6
  1. Architecture20%
  2. Controller Deployment15%
  3. Router Deployment20%
  4. Policies20%
  5. Security and Quality of Service15%
  6. Management and Operations10%
  1. 1

    A network engineer wants to verify the Bidirectional Forwarding Detection (BFD) sessions and their status on all active WAN tunnels of a cEdge router. Which CLI command should the engineer use to display this information?

    Show answer details

    Correct answer: C

    The show sdwan bfd sessions command on a cEdge (IOS XE SD-WAN) router provides a detailed list of all BFD sessions. The output includes the source and destination TLOCs, the state of the session (Up/Down), uptime, and detection time, which is essential for troubleshooting data plane connectivity issues.

  2. 2

    True or False: A centralized control policy in Cisco SD-WAN is used to directly manipulate the path of data packets for specific applications as they traverse the fabric.

    Show answer details

    Correct answer: B

    This statement is false. A centralized control policy operates on the control plane. It influences routing decisions by manipulating OMP route advertisements (vRoutes and TLOC routes), which in turn determines the overall network topology. A centralized data policy is used to directly manipulate the path of data packets based on criteria like source/destination IP, port, or DSCP value.

  3. 3

    An organization is deploying an application-aware routing policy to steer real-time voice traffic over the link with the lowest latency. The policy is configured with an SLA class that has a maximum latency threshold of 150 ms. The MPLS link is currently measured at 100 ms latency, and the Internet link is at 160 ms. How will the SD-WAN fabric handle the voice traffic?

    Show answer details

    Correct answer: B

    Application-aware routing policies first identify all paths that meet the defined SLA criteria. In this case, only the MPLS link (100 ms) is within the 150 ms latency threshold. The Internet link (160 ms) violates the SLA. Therefore, all voice traffic will be sent exclusively over the MPLS link as it is the only compliant path.

  4. 4

    A network administrator is configuring a vEdge router for a new branch. The configuration requires a subinterface on a physical port to handle tagged VLAN traffic for a specific service VPN. Which configuration snippet correctly creates a VLAN-tagged subinterface and assigns it to VPN 10?

    # The physical interface is ge0/1
    # The VLAN ID is 100
    # The service VPN is 10
    
    Show answer details

    Correct answer: C

    On a vEdge router (Viptela OS), a subinterface is created by appending a dot and the subinterface number (which is conventionally the VLAN ID) to the physical interface name (e.g., ge0/1.100). The VLAN tag is implicitly defined by this syntax when the subinterface is configured under a service VPN. This subinterface is then configured with an IP address and brought up like a regular interface.

  5. 5

    What are two primary functions of the Overlay Management Protocol (OMP) in a Cisco SD-WAN fabric? (Select TWO)

    Show answer details

    Correct answer: B, E

    OMP is responsible for the distribution of IPsec encryption keys between WAN Edge routers, which is essential for establishing the data plane tunnels.

    This is the core function of OMP. It acts as the routing protocol for the overlay, advertising service-side prefixes (vRoutes), data plane tunnel endpoints (TLOCs), and policies between the vSmart controllers and WAN Edge routers.

  6. 6

    A financial services company is deploying a Cisco SD-WAN fabric and requires that all traffic destined for its PCI-compliant datacenter traverses a specific high-security MPLS circuit. However, all other traffic, including general internet access, should use a commodity broadband circuit for cost savings. Which policy configuration is the most direct and efficient way to achieve this segmentation and traffic steering?

    Show answer details

    Correct answer: A

    A centralized data policy using an 'app-route' action is the correct method for influencing the path of specific traffic flows based on destination prefixes and directing them to a preferred TLOC (in this case, the MPLS circuit). This allows granular control over traffic steering within the SD-WAN fabric. A control policy manipulates routing updates, not data traffic paths directly. Localized policies apply only to a single device and are less scalable for fabric-wide rules. A VPN membership policy controls which sites can communicate within a VPN, but not the path they take.

  7. 7

    During a vSmart controller software upgrade, an administrator needs to ensure that WAN Edge routers retain their OMP routing information and that the data plane remains fully operational without interruption. Which OMP feature must be enabled on the WAN Edge routers to support this requirement?

    Show answer details

    Correct answer: C

    OMP Graceful Restart is a mechanism that allows a WAN Edge router to continue forwarding traffic using its last known OMP routing information when its control plane connection to the vSmart controller is lost. This prevents traffic black-holing during controller reboots or upgrades. The hold-down timer is for route stability, BFD detects path failures, and route polling is not a standard OMP feature.

  8. 8

    A network engineer is configuring a QoS map policy to prioritize VoIP traffic (marked with DSCP EF) and ensure it receives preferential treatment across the SD-WAN fabric. The policy needs to allocate bandwidth and schedule traffic appropriately. Which set of actions within a centralized data policy is required to achieve this? (Select TWO)

    Show answer details

    Correct answer: C, E

    Setting the forwarding class maps the matched traffic (e.g., DSCP EF) to a specific hardware queue on the WAN Edge router. This is the first critical step in applying QoS treatment.

    After mapping traffic to a forwarding class, you assign that class to a specific queue defined in the QoS map. This queue will have properties like bandwidth percentage and scheduling priority (e.g., Low Latency Queuing).

  9. 9

    True or False: In a Cisco SD-WAN architecture, the vBond orchestrator is responsible for building and maintaining the IPsec tunnels that form the data plane between WAN Edge routers.

    Show answer details

    Correct answer: B

    This statement is false. The vBond orchestrator's primary roles are initial authentication, NAT traversal facilitation, and distributing the list of vSmart controllers to WAN Edge routers. The WAN Edge routers themselves are responsible for establishing and maintaining the IPsec data plane tunnels between each other, using the routing and key information provided by the vSmart controllers.

  10. 10

    A retail company has deployed dual WAN Edge routers at a critical branch location for high availability. A point-of-sale (POS) server segment is connected to a Layer 2 switch, which in turn is dual-homed to both WAN Edge routers. The network architect wants to provide active/active forwarding for the POS segment across both routers' WAN links without implementing a traditional FHRP like VRRP or HSRP on the service side.

    +-----------+ +-----------+
    MPLS--| vEdge-A |------| vEdge-B |--INET
    +-----------+ +-----------+
    | |
    +--------+---------+
    |
    +-----------+
    | L2 Switch |
    +-----------+
    |
    [POS Servers]
    

    Which Cisco SD-WAN feature should be configured on the service-side interfaces of vEdge-A and vEdge-B to achieve this goal?

    Show answer details

    Correct answer: B

    TLOC Extension is a feature designed for this exact scenario. It allows a WAN Edge router to extend its transport location (TLOC) to another physically connected WAN Edge router over a service-side connection. This enables the second router to use the first router's WAN links, and vice versa, providing active/active forwarding and path redundancy for the service-side segment without needing an FHRP.

Create an account to continue.