300-440 Practice Questions
Prepare for 300-440 with more than an answer.
- Exam fee
- $300 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 5
- Architecture Models15%
- Design15%
- IPsec Cloud Connectivity25%
- SD-WAN Cloud Connectivity25%
- Operation20%
- 1
An organization requires a multi-cloud connectivity solution with global reach, on-demand bandwidth, and predictable latency. An architect is evaluating Software-Defined Cloud Interconnect (SDCI) providers. Which THREE of the following are key characteristics of an SDCI solution that meet these requirements? (Select THREE)
Show answer details
Correct answer: B, C, E
SDCI providers operate their own private backbone, which ensures predictable latency and performance by avoiding the public internet.
The 'Software-Defined' aspect means connectivity can be rapidly provisioned, modified, and de-provisioned through a self-service portal or API, enabling on-demand bandwidth.
SDCI providers build direct, dedicated entry points into cloud provider networks (like AWS Direct Connect, Azure ExpressRoute), which is fundamental to their service offering.
- 2
A network engineer is troubleshooting a Cisco SD-WAN deployment where branch routers are unable to form control connections with the vSmart controller. The vBond orchestrator is reachable. What is the most likely cause for this specific failure?
Show answer details
Correct answer: C
All control connections in Cisco SD-WAN are secured with DTLS/TLS and rely on certificates for authentication. If the system clock on the vEdge is significantly out of sync, the validity period of the vSmart controller's certificate will appear incorrect to the vEdge. This causes the certificate validation to fail, preventing the DTLS control connection from being established. Since vBond was reachable, initial authentication and IP discovery worked, pointing to a problem with the subsequent connection to vSmart.
- 3
When designing a secure connection from an on-premises data center to a public cloud provider, which statement accurately describes the security responsibilities for east-west traffic within a Virtual Private Cloud (VPC)?
Show answer details
Correct answer: B
Under the shared responsibility model, the cloud provider secures the underlying infrastructure, but the customer is responsible for security in the cloud. This includes configuring network controls for east-west traffic (traffic between resources within the VPC). Customers must use services like AWS Security Groups/NACLs, Azure Network Security Groups (NSGs), or Google Cloud Firewall Rules to implement micro-segmentation and control communication between their own virtual machines and services.
- 4
An e-commerce company experiences intermittent packet loss and high latency for its application servers hosted in an Azure VNet. The application servers are connected to an on-premises database via a site-to-site IPsec VPN terminated on a Cisco IOS XE router. The issue is most prevalent during peak business hours.
An investigation reveals that the IPsec tunnel itself is stable. The output of
show crypto ipsec sashows no increase in decapsulation errors, but theshow policy-map interface Tunnel0command indicates a high number of drops in the outbound queue. The physical internet connection has ample bandwidth. The following diagram shows the logical setup.What is the most likely cause of the performance degradation?
Show answer details
Correct answer: D
This is the classic cause for such symptoms. IPsec adds encapsulation overhead, reducing the effective MTU of the tunnel. If large packets (e.g., 1500 bytes) are sent through the tunnel without adjustment, the router must fragment them, which is a CPU-intensive process. During peak hours, the high volume of packets needing fragmentation overwhelms the router's CPU, causing it to drop packets in its output queue. The solution is to set
ip mtuon the tunnel interface (e.g., to 1400) and configureip tcp adjust-mss(e.g., to 1360) to prevent fragmentation from occurring. - 5
A global logistics company with regional hubs in North America, Europe, and Asia is designing a multi-cloud strategy using AWS, Azure, and Google Cloud. Each region has its own set of applications and data sovereignty requirements. The company wants to optimize for regional performance, allowing local traffic to access cloud resources within the same continent, while also enabling secure inter-regional back-end traffic. Management requires a solution that is centrally managed but regionally autonomous.
Which architecture model provides the best solution?
graph TD subgraph NA["North America"] DC_NA[On-Prem DC] VPC_NA[AWS VPC] VNET_NA[Azure VNet] end subgraph EU["Europe"] DC_EU[On-Prem DC] VPC_EU[AWS VPC] VNET_EU[Azure VNet] end subgraph AP["Asia-Pacific"] DC_AP[On-Prem DC] VPC_AP[AWS VPC] VNET_AP[Azure VNet] end Internet((Internet)) --> GlobalFabric GlobalFabric{Cisco SD-WAN Fabric} --> NA GlobalFabric --> EU GlobalFabric --> APShow answer details
Correct answer: C
This is the ideal architecture. A global SD-WAN fabric provides central management (via vManage) and policy enforcement. Deploying vSmart controllers regionally allows for regional autonomy and reduces control plane latency. Cloud OnRamp for IaaS automates the deployment of vEdge Cloud routers in each cloud provider and the creation of secure tunnels. Application-aware routing policies can then be used to ensure local traffic prefers in-region cloud resources, while centralized data policies can securely enable specific inter-regional traffic flows. This model perfectly balances central control with regional performance.
- 6
A financial services company is establishing a highly resilient connection to an AWS region using two separate 10 Gbps Direct Connect circuits from different providers. To meet compliance requirements, the design must ensure that a failure of a single device on either the on-premises or AWS side does not disrupt connectivity. Which design provides the highest level of resiliency?
Show answer details
Correct answer: C
This design provides the highest resiliency by eliminating single points of failure. Using different on-premises routers protects against a device failure on the customer side. Using separate Direct Connect gateways protects against a logical failure within the AWS Direct Connect service. Attaching both to a Transit Gateway allows for centralized routing and seamless failover between the paths. Terminating on a single router or VGW introduces a single point of failure.
- 7
A network engineer is troubleshooting a newly configured IPsec VPN tunnel between an on-premises Cisco IOS XE router and an Azure VPN Gateway. The tunnel fails to establish. The engineer runs the command
show crypto isakmp saand sees the tunnel state asMM_NO_STATE. What is the most likely cause of this issue?Show answer details
Correct answer: C
The
MM_NO_STATEstatus indicates that the initiator (the Cisco router) sent the initial IKE Main Mode (MM) packets but received no response from the peer (Azure VPN Gateway). This almost always points to a connectivity issue where the IKE negotiation packets (UDP port 500 for ISAKMP) are being blocked by a firewall, an ACL, or a routing problem. Phase 2 mismatches would occur after Phase 1 is complete, and BGP issues are irrelevant to the IPsec tunnel establishment itself. - 8
An organization is deploying Cisco SD-WAN and wants to optimize Microsoft 365 performance for its branch offices using Cloud OnRamp for SaaS. The goal is to send Microsoft Teams traffic directly to the internet over the best-performing path, while all other Microsoft 365 traffic is backhauled to a regional data center for inspection. Which two policy types must be configured in vManage to achieve this? (Select TWO)
Show answer details
Correct answer: B, D
The Application-Aware Routing (AAR) policy is used to identify Microsoft Teams traffic and steer it onto the path that meets the defined SLA (e.g., lowest latency), enabling the direct internet access.
A Centralized Data Policy is required to create the traffic engineering logic. It will match the non-Teams Microsoft 365 traffic and direct it towards the service VPN that leads to the regional data center, while allowing the Teams traffic (handled by the AAR policy) to exit locally.
- 9
A global enterprise with data centers in multiple continents needs to establish private, low-latency connectivity to several VPCs in AWS and VNETs in Azure. The CISO has mandated that traffic must not traverse the public internet. The solution must be scalable to add new cloud regions and providers with minimal effort. Which architecture model best fits these requirements?
Show answer details
Correct answer: C
An SDCI provider (like Megaport or Equinix Fabric) offers a private, high-speed backbone that connects to major cloud providers globally. This model allows the enterprise to connect its data centers to the SDCI fabric once and then programmatically spin up virtual cross-connects to various cloud regions and providers. This meets the requirements for private connectivity, low latency, and scalability without the complexity and cost of managing numerous individual private circuits.
- 10
True or False: When using Cisco SD-WAN to connect to a SaaS provider like Salesforce, the Cloud OnRamp for SaaS feature primarily relies on BGP for path selection to the SaaS application front door.
Show answer details
Correct answer: B
This statement is false. Cisco SD-WAN Cloud OnRamp for SaaS does not use BGP for path selection. Instead, it continuously probes the SaaS application over all available paths using HTTP probes. It then calculates a quality of experience (QoE) score based on latency and loss, and steers user traffic down the best-performing path in real-time. BGP is used for underlay or overlay routing, not for the dynamic, application-level path selection specific to this feature.
