300-415 — Frequently Asked Questions

Community-vetted answers to 50 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

Impacts of Losing vManage Connectivity to Cisco SD-WAN Fabric

Yes, you can create and edit templates in the vManage GUI/database. The limitation is only that these templates cannot be pushed (propagated) to the WAN Edge devices.

No, IPsec tunnels are established and maintained directly between WAN Edge devices. They do not depend on vManage connectivity to stay up.

Cisco SD-WAN TCP Optimization Functions

Local termination allows the SD-WAN device to handle retransmissions over the WAN link, preventing end-host timeouts due to high latency or packet loss.

SACK allows the receiver to acknowledge non-contiguous blocks of received data, enabling faster and more efficient retransmission of only lost packets.

Which Component Creates a Feature Profile in Cisco SD-WAN UX 2.0?

Feature parcels are the configuration blocks inside a feature profile; the Feature Profile itself is created and organized under a Configuration Group in UX 2.0.

No. Feature templates belong to the older UX 1.0 workflow; UX 2.0 uses Configuration Groups containing Feature Profiles built from Feature Parcels.

What Must Be Defined for SD-WAN Application-Aware Routing?

Application-aware routing matches on application signatures, not on prefixes. The policy is scoped to a VPN and site list, so a prefix list is unnecessary.

No separate color list is mandatory, but the TLOC colors (e.g., MPLS, public internet) must be configured on the interfaces before you can select a preferred color.

WAN Edge Registration with Enterprise CA Certificates

In the Enterprise CA model, the vManage controller manages the certificate lifecycle. The edge trusts the vManage, so the vManage generates the CSR and installs the final cert to authenticate the edge.

Manual CA requires the edge to handle all CSR and installation steps. Enterprise CA integrates with a corporate PKI where vManage facilitates the signing process, simplifying edge management.

How Many NICs Does vSmart Need on VMware ESXi?

Cisco's vSmart ESXi deployment uses one NIC for management and control connectivity and a second for data/overlay traffic, so a single vNIC is not enough.

No; vSmart uses two vNICs, while vManage and other SD-WAN components have their own separate VM resource and NIC requirements.

What Is the BFD Multiplier in Application-Aware Routing?

Six is the default multiplier that averages the last six poll intervals for AAR SLA classification; seven is the separate default multiplier used for tunnel liveness detection.

It multiplies the poll interval to define how far back AAR looks when calculating mean loss, mean latency and mean jitter for the tunnel.

What Is Required for On-Premises vBond via PnP Connect?

vManage can be configured manually without direct Internet access; the vBond controller itself reaches the PnP Connect service to obtain its configuration.

Yes, the controller profile can use an IP address to identify vBond; DNS is not a strict requirement for the PnP Connect deployment process.

Where to Map a New QoS Class to a Queue in vManage?

Queue mapping ties a forwarding class to a platform-specific hardware queue, so it is a per-device Local Policy list; Centralized Policy is for fabric-wide intent like topology and app-route.

The WAN interface (VPN0) is the transport egress where congestion and scheduling occur, so SD-WAN QoS maps are attached there; service-side QoS is LAN-facing and does not protect WAN transport.

Which SD-WAN Policy Keeps Voice on a Link Below 50 ms Delay?

A localized data policy only does per-interface QoS (classification, marking, shaping, queuing). It cannot probe tunnels or move the voice flow to a link with lower delay.

A centralized data policy binds voice traffic to an SLA class; vSmart programs BFD-based probing and the routers forward voice over the tunnel whose delay, jitter and loss meet that class.

Which VPNs Must Be Configured Outside the SD-WAN Quick Connect Workflow?

Quick Connect only configures WAN transport settings in VPN 0, so service-side VPN templates must be added separately to complete the SD-WAN overlay and carry service traffic.

No, Quick Connect focuses on WAN transport VPN 0; management and service VPNs are outside its scope, and only service VPNs are required to finish the overlay bring-up.

How Many vBond Controllers Are Needed for Four SD-WAN Tenants?

No. The vBond orchestrator is shared across all tenants, so four tenants still use one shared vBond (A).

Cisco SD-WAN does not require three vBond controllers in multitenancy; the orchestrator count is not tied to tenant count, and a single shared vBond serves all tenants.

Configuring OSPF Summary Routes to ASBR in SD-WAN

It forces the router to use the older RFC 1583 metric calculation for inter-area paths, which differs from the newer RFC 2328 method.

Originate controls whether the router generates summary LSAs, while RFC 1583 Compatible controls how the cost of those routes is computed.

Cisco SD-WAN Multi-Region Fabric Capability

No, each region typically has its own set of vSmart controllers. They establish IPsec tunnels with each other for control plane communication.

Yes, SLA-based routing is available within each region. However, the defining feature for inter-region traffic is the encrypted tunnel provided by Multi-Region Fabric.

Cisco SD-WAN Packet Duplication Process

Yes, it significantly increases bandwidth consumption because duplicate traffic is transmitted on all selected paths.

Enable it only for critical applications where packet loss causes unacceptable jitter or latency, due to the high bandwidth cost.

Cisco SD-WAN vEdge Advanced Security Features

While AMP integrates with SD-WAN, the 'Threat Grid' component mentioned is a cloud-based sandbox, not a local feature running on the vEdge router.

No, Snort IPS is not a built-in feature of the Cisco Catalyst SD-WAN software; you would typically use the Enterprise Firewall or integrate with a separate IPS appliance.

SD-WAN TLOC Selection with SLA and Application-Aware Routing

SLA acts as a filter. If both meet SLA and no preferred color is set, the path with the best underlying metrics (latency/loss) is chosen.

Without explicit ECMP configuration, SD-WAN selects a single best active path based on policy and metrics, not load balancing.

Cisco TrustSec SGT Propagation Methods

Inline tagging embeds the SGT in the data frame (Layer 2), while SXP maps IP addresses to SGTs over TCP (Layer 3) for devices that cannot modify frames.

No, offline tagging implies manual or delayed assignment. Real-time propagation requires either inline tagging or SXP to ensure immediate policy enforcement.

Cisco SD-WAN Controller for Provisioning and Configuration

vManage is the management plane for provisioning and configuration via a GUI/API. vSmart is the control plane that distributes routing policies and maintains control sessions between WAN Edge routers.

No, vBond is strictly an orchestrator. It authenticates devices, discovers controllers, and facilitates NAT traversal, but it does not push configurations or manage the network state.

REST API for Real-Time Application-Aware Routing Monitoring

It provides live statistics on data traffic characteristics for operational tunnels, reflecting current routing performance.

It typically offers historical or aggregated data rather than the immediate real-time status needed for active monitoring.

What Is a Key Element in vBond Orchestrator Redundancy?

Although a load balancer can optionally front vBond orchestrators, the universal requirement is an FQDN that resolves to the vBond IPs; the load balancer still uses a virtual FQDN.

No, STUN is used for NAT traversal to help vEdge devices discover their public IP, not for vBond redundancy.

Which Signature Sets Are Available in vManage for IPS?

Malware protection is handled by separate Cisco SD-WAN security features, while the IPS signature sets selectable in vManage security policy are only Connectivity, Balanced, and Security.

Yes. Balanced is one of the three predefined IPS signature sets in vManage, along with Connectivity for higher throughput and Security for stricter inspection.

What Is the Role of the vBond STUN Server in Cisco SD-WAN NAT Traversal?

STUN on vBond does not keep Edge routers behind a NAT firewall while controller addresses stay unNAT-ed; it reports back each device's translated IP and port so correct TLOCs and tunnels can be built.

No. STUN address discovery applies to any transport where NAT translation occurs, such as broadband or LTE internet links, not just MPLS TLOCs as option C claims.

Which Application List Is Preconfigured in Cisco SD-WAN vManage?

The only Microsoft factory list in vManage is named Microsoft_Apps. Microsoft_Office365 is not shipped by default and must be created or selected from DPI-recognized SaaS applications.

No. Both preconfigured lists are read-only: you can view their entries and reference them in policies, but you cannot edit or delete them.

IPsec Rekey Timer for a 24-Hour OMP Graceful Restart?

The IPsec SA must outlive the entire OMP restart window so tunnels are not torn down while OMP is recovering; doubling the restart interval guarantees the SA stays valid.

No. 36 hours is only 1.5× the restart interval, and the rekey timer must be at least 2× that value, so 48 hours is the minimum valid setting.

Ready to practice?

Access 120 300-415 questions with instant feedback and detailed explanations.

View 300-415 Practice Questions →

← Back to 300-415 Implementing Cisco Catalyst SD-WAN Solutions Study Guide