VNX100 Versa Certified Sd-WAN Associate Practice Questions
Prepare for VNX100 with more than an answer.
- Exam fee
- $100 USD
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 6
- SD-WAN Fundamentals and Architecture20%
- Versa Secure SD-WAN Platform Components25%
- Control and Data Plane Functions20%
- CPE Provisioning and Deployment15%
- SD-WAN Services20%
- Monitoring, Reporting, and Troubleshooting20%
- 1
An administrator is creating a custom application definition for an internal, non-standard TCP-based application that runs on port 8443. This application needs to be prioritized by a QoS policy. Which parameters can be used within the Versa application definition to uniquely identify this traffic? (Select THREE)
Show answer details
Correct answer: A, B, D
Specifying the IP protocol (e.g., TCP (6) or UDP (17)) is a fundamental part of the application signature.
The destination port (8443 in this case) is a primary identifier for server-side applications.
Using the IP address or subnet of the application server provides a highly specific match criteria, ensuring only traffic to that server is identified.
- 2
What is the primary function of BGP within the Versa Secure SD-WAN control plane?
Show answer details
Correct answer: B
Versa utilizes Multiprotocol BGP (MP-BGP) as the primary routing protocol for its control plane. Each CPE establishes a BGP peering session with the Versa Controllers. The CPEs advertise their local LAN prefixes to the Controllers, which then reflect these routes to all other CPEs in the same organization. This allows all sites to learn about the network prefixes available at every other site, establishing overlay reachability.
- 3
A network engineer is troubleshooting why a specific traffic flow is not being load-balanced across two active WAN links as expected. The engineer has confirmed that the SD-WAN Forwarding Profile is configured for load balancing. What is a common reason that a stateful service, such as a firewall, would prevent per-packet load balancing from functioning correctly?
Show answer details
Correct answer: C
Stateful firewalls maintain a session table to track active connections. They expect to see all packets for a given session, including the return traffic, traverse the same path. Per-packet load balancing breaks this by sending different packets of the same session over different links. This creates asymmetric routing. When return traffic for a packet sent on Link B arrives on Link A, the firewall on Link A has no record of that session and will drop the packet, breaking the connection. This is why per-flow load balancing is typically used with stateful services.
- 4
When reviewing a dashboard in Versa Analytics, a network operator notices a critical 'Controller Unreachable' alarm for a branch device. What is the immediate impact on the data plane for that branch?
Show answer details
Correct answer: B
Due to the separation of the control and data planes, a loss of connectivity to the Versa Controller does not cause an immediate data plane outage. The CPE device will continue to forward traffic based on the forwarding information base (FIB) and policies it last received from the Controller. However, it will be unable to receive any updates, such as new routes or policy changes, and cannot adapt to topology changes in the rest of the SD-WAN fabric until connectivity is restored.
- 5
A Versa SD-WAN is configured in a hub-and-spoke topology. An engineer needs to allow two spoke sites to communicate directly with each other for a specific application to reduce latency, without converting the entire network to a full mesh. What Versa feature can achieve this?
flowchart TD subgraph Data Center Hub[Hub CPE] end subgraph Branch Offices SpokeA[Spoke A] SpokeB[Spoke B] SpokeC[Spoke C] end SpokeA -- Overlay Tunnel --> Hub SpokeB -- Overlay Tunnel --> Hub SpokeC -- Overlay Tunnel --> Hub SpokeA -.-> SpokeBShow answer details
Correct answer: B
Versa supports the creation of dynamic, on-demand tunnels between spoke sites. This is typically triggered by a traffic steering policy that identifies specific application traffic between two spokes. When this traffic is detected, the spokes dynamically build a direct IPsec tunnel between themselves for that session, bypassing the hub and reducing latency. This provides the benefits of a mesh topology for specific flows without the overhead of a full mesh.
- 6
A financial services firm is deploying Versa Secure SD-WAN to connect its branch offices to a central data center. The firm has a strict compliance requirement that all traffic destined for the internet from the branches must be inspected by a centralized next-generation firewall (NGFW) cluster located at the data center. Which configuration element is most critical for enforcing this traffic pattern?
Show answer details
Correct answer: B
To meet the requirement of forcing all branch internet traffic through a centralized NGFW at the data center, the correct approach is to configure a traffic steering policy. This policy should match all internet-bound traffic (represented by the default route 0.0.0.0/0) and direct it through the secure SD-WAN overlay tunnels to the data center hub. This process is known as backhauling. A DIA policy would send traffic directly to the internet from the branch, bypassing the central firewall. A QoS policy only prioritizes traffic, it doesn't control its path. A full mesh topology defines branch-to-branch connectivity but does not enforce centralized internet egress.
- 7
During a Zero Touch Provisioning (ZTP) process for a new branch appliance, the device successfully contacts the Versa redirection server and receives the bootstrap URL for its organization's Versa Director. However, the process fails shortly after. An administrator confirms the appliance has internet connectivity and can resolve DNS. Which of the following are the two most probable causes for this failure? (Select TWO)
Show answer details
Correct answer: A, C
If the device's serial number is not in the Versa Director inventory, the Director will reject the onboarding request, causing the ZTP process to fail after the initial contact.
The branch appliance communicates with the Versa Director over HTTPS to download its configuration. If this port is blocked by an intermediate firewall, the ZTP process will fail at this stage.
- 8
An administrator is configuring a traffic steering policy to optimize Office 365 performance. The policy is designed to prefer a low-latency broadband circuit over a high-latency MPLS circuit. However, if the broadband circuit's latency exceeds 50ms, the traffic should fail over to the MPLS circuit. Which Versa component is responsible for actively measuring the circuit latency to enable this policy decision?
Show answer details
Correct answer: C
The Versa Operating System (VOS) running on the branch CPE is responsible for generating and sending SLA probes across the available WAN paths to measure real-time performance metrics like latency, jitter, and packet loss. These measurements are then used by the traffic steering engine on the CPE to make dynamic path selection decisions based on the configured policies. Versa Director is for management, and Versa Analytics is for historical data, while the Controller manages the control plane.
- 9
True or False: In a Versa Secure SD-WAN deployment, the Versa Controller is responsible for processing and forwarding all data plane traffic between branch sites in a hub-and-spoke topology.
Show answer details
Correct answer: B
This statement is false. The Versa Controller operates on the control plane. It is responsible for establishing and maintaining the routing and policy information for the SD-WAN fabric. The actual data plane traffic is forwarded directly between the Versa CPE appliances (spokes) and the hub appliance, or directly between spokes in a mesh topology. The Controller facilitates the setup of these data paths but does not sit in the path of the data itself.
- 10
An organization is migrating from a legacy MPLS network to a Versa SD-WAN solution. They need to maintain connectivity between the new SD-WAN sites and the remaining legacy MPLS sites during a phased rollout. Which Versa component is specifically designed to act as a gateway between the SD-WAN overlay and the MPLS L3-VPN underlay?
Show answer details
Correct answer: D
The Versa Gateway is the component specifically designed for interconnecting the SD-WAN overlay fabric with traditional WAN underlays like MPLS L3-VPNs. It facilitates route exchange and data plane forwarding between the two disparate networks, enabling a seamless migration and hybrid WAN operation. While a hub CPE can centralize traffic, the Gateway role has specific features for this MPLS integration purpose.
