WAN Edge Registration with Enterprise CA Certificates
Refer to the exhibit. Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two.) - 
Community Votes
53% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between manual CSR generation on the edge versus controller-managed CSR generation when using an Enterprise CA in a multi-controller environment.
This page explains the correct certificate workflow for registering Cisco SD-WAN WAN Edges to vManage controllers using an Enterprise CA. It clarifies that CSR generation must occur on the controller (vManage) and certificates must be installed there, distinguishing this from manual edge-based enrollment.
Many learners choose A and E because they assume the edge device must generate its own CSR and request the certificate manually, which is incorrect for the standard Enterprise CA integration pattern shown in the exhibit.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When integrating Cisco SD-WAN WAN Edges with an Enterprise CA in a multi-vManage environment, the recommended and supported workflow involves the vManage controllers handling the Certificate Signing Request (CSR) generation. Option B is correct because you must generate the CSR within the vManage server (or via the vManage API/UI) so it can sign the certificate against the Enterprise CA. Option D is correct because the resulting signed certificate must be installed on the vManage controller to facilitate the trust chain for the WAN Edges. This allows the WAN Edges to register securely without needing direct access to the CA or manual certificate management on every edge device.Why the Other Options Are Wrong
Options A, C, and E describe a manual enrollment process where the edge generates a CSR (C), requests the cert (E), and installs it (A). While technically possible in isolated setups, this is not the standard 'Enterprise CA' configuration implied by the exhibit and exam doctrine for registered WAN Edges. The term 'registered' implies the controller manages the identity. Option C is wrong because generating CSRs manually on the WAN Edge bypasses the controller's ability to manage the certificate lifecycle. Option E is wrong because the edge does not directly request certificates from the Enterprise CA in this architecture; the vManage acts as the intermediary.Community Comment Notes
Community discussion is split between BD and AE. Users like Networkchamp87 and Knowledge33 correctly identify BD based on official Cisco deployment guides. However, several users (e.g., PureInertiaCopy, Outlaw_87) argue for AE, citing lab experiences or specific manual configurations. One user noted that if the picture shows 'Enterprise', it implies the CA is already trusted, but the exam question specifically asks for the configuration needed to get them registered, which points to the controller-side actions. As one commenter stated, 'Process for that is B,D,' aligning with the official SD-WAN Controller Certificate Deploy Guide.Official Reference
Exam Strategy
For SD-WAN security questions involving 'Enterprise CA' and 'Registration', always look for options where the vManage controller handles the CSR and certificate installation. Avoid options that suggest manual interaction on the WAN Edge unless the question explicitly states 'Manual Enrollment'.
Frequently Asked Questions
Why can't the WAN Edge generate its own CSR?
In the Enterprise CA model, the vManage controller manages the certificate lifecycle. The edge trusts the vManage, so the vManage generates the CSR and installs the final cert to authenticate the edge.
What is the difference between Manual and Enterprise CA?
Manual CA requires the edge to handle all CSR and installation steps. Enterprise CA integrates with a corporate PKI where vManage facilitates the signing process, simplifying edge management.
Related Analysis
Practice All 300-415 Questions
Access 120 questions with complete answers and detailed explanations.
View Full 300-415 Practice Test →