Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) · Difficulty

Hard 300-440 practice questions

Challenge — multi-step scenarios, trade-offs, and subtle distinctions. 46 hard questions available — no sign-up, always free.

Question 1 of 25

A financial services company already has a 10 Gbps AWS Direct Connect dedicated connection terminating at a colocation facility. The network team now needs to give an internal analytics application private, low-latency access to a third-party market-data SaaS offering that is published through AWS PrivateLink in a provider VPC. The traffic must never traverse the public internet, and the team wants to avoid provisioning a second physical circuit. Which approach lets them consume this SaaS service over their existing Direct Connect?

Reviewed for accuracy · Report an issue
Question 2 of 25

A financial services company must connect its on-premises data center to AWS using a dedicated private circuit. A security requirement states that all data traversing the Layer 2 link between the customer premises and the AWS Direct Connect location must be encrypted at line rate without adding routing overhead or reducing throughput. The design team wants to satisfy this at the physical link layer rather than relying on an IPsec tunnel over the connection. Which capability should the design recommend?

Reviewed for accuracy · Report an issue
Question 3 of 25

A financial services company runs a data-analytics application in an on-premises data center connected to AWS via an existing Direct Connect private VIF and a Direct Connect gateway. The security team mandates that traffic to Amazon S3 for storing regulatory reports must never traverse the public internet and must not require adding public IP prefixes to the Direct Connect public VIF. Which AWS connectivity construct should the network architect deploy to reach the S3 service privately over the existing private connectivity?

Reviewed for accuracy · Report an issue
Question 4 of 25

A financial services company is migrating a latency-sensitive trading analytics workload to Azure. Requirements include: a consistent 5 Gbps of throughput, BGP-based dynamic routing between on-premises and Azure, redundancy across two physically diverse paths at the peering location, and the ability to advertise the same on-premises prefixes over both paths for active/active load distribution. Which connectivity design best satisfies these network architecture requirements?

Reviewed for accuracy · Report an issue
Question 5 of 25

A U.S. federal agency contractor is migrating a sensitive workload to AWS GovCloud. Compliance mandates that the workload meet FedRAMP High requirements, and that all data in transit between the on-premises data center and the cloud must never traverse the public internet. The security team also requires that connectivity avoid shared transport infrastructure to reduce the risk of data commingling with other tenants. Which connectivity model should the network architect recommend?

Reviewed for accuracy · Report an issue
Question 6 of 25

A financial services company runs its data analytics platform in Google Cloud and consumes BigQuery and Cloud Storage as managed SaaS-like services. Compliance rules prohibit any of this traffic from traversing the public internet, and the security team requires that the Google APIs be reached over the private/restricted Google API VIP range (not the public internet) from the on-premises data center over an existing Dedicated Interconnect. Which Google Cloud feature should the network architect configure to meet these requirements?

Reviewed for accuracy · Report an issue
Question 7 of 25

A network engineer is establishing a site-to-site VPN from an on-premises Cisco IOS XE router to a native AWS Virtual Private Gateway (VGW). AWS has generated a configuration file specifying two tunnels, each with a pre-shared key and an inside tunnel address in the 169.254.0.0/16 range. The engineer wants dynamic route exchange over the tunnels using BGP. When configuring the IOS XE tunnel interfaces to match the AWS native endpoint, which combination correctly reflects how the tunnel must be built?

Reviewed for accuracy · Report an issue
Question 8 of 25

A network engineer is configuring a route-based IPsec (VTI) tunnel from an on-premises Cisco IOS XE router to a native Azure VPN Gateway (route-based, Generation 2). The IKEv2 SA is failing to establish, and debugs on the IOS XE router show the negotiation stalling during the IKE_SA_INIT exchange. The engineer confirms that the pre-shared key, IKEv2 encryption, and integrity algorithms are all correctly matched to Azure's default IPsec/IKE policy. Which additional IKEv2 proposal parameter must the engineer verify matches the Azure default policy to allow IKE_SA_INIT to complete?

Reviewed for accuracy · Report an issue
Question 9 of 25

A network engineer is designing GRE-over-IPsec connectivity from an on-premises Cisco IOS XE router to a native Azure VPN Gateway (not a cloud-hosted IOS XE instance). The design requires a routed tunnel interface running BGP over the encrypted overlay. During testing, IKEv2 and IPsec SAs come up successfully, but the GRE tunnel interface never reaches the up/up state and no BGP session forms. What is the most likely root cause of this failure?

Reviewed for accuracy · Report an issue
Question 10 of 25

A network engineer is building a GRE over IPsec tunnel from an on-premises Cisco IOS XE router to a Cisco IOS XE router hosted in AWS. Both sides use IKEv2 with pre-shared key authentication. The IKEv2 SA comes up intermittently and the logs on the on-premises router show 'IKEv2 profile not found' during some negotiations, even though a single IKEv2 profile is configured. The peer sits behind a NAT device, so the source address seen for its IKE negotiations does not match the address configured in the profile. What is the most likely configuration cause and the correct fix?

Reviewed for accuracy · Report an issue
Question 11 of 25

A network engineer is designing GRE over IPsec connectivity from an on-premises Cisco IOS XE router to a native Google Cloud HA VPN gateway. The engineer initially proposed running a GRE tunnel encapsulated in IPsec directly to the Cloud VPN gateway endpoint. During validation, the tunnel to the native Cloud VPN gateway will not establish the GRE overlay. What is the correct explanation and remediation for connecting to the native Google Cloud VPN endpoint?

Reviewed for accuracy · Report an issue
Question 12 of 25

A network engineer is building a GRE over IPsec tunnel from an on-premises Cisco IOS XE router to a cloud-hosted Cisco IOS XE router in AWS to run eBGP across the overlay. After configuring the IPsec profile, tunnel interface, and BGP peering over the tunnel IP addresses, the IPsec SA comes up and the BGP session reaches Established, but it repeatedly resets once the peers exchange their full routing tables, and large file transfers across the tunnel stall. The tunnel source is a public interface behind a 1500-byte MTU internet path. What is the MOST likely cause and the correct remediation?

Reviewed for accuracy · Report an issue
Question 13 of 25

A retail company hosts its inventory microservices on Cisco Catalyst SD-WAN branch routers that must reach an application published in a partner's AWS VPC. The partner exposes the application only through an AWS PrivateLink endpoint service and will not accept traffic over the public internet. The company already terminates its cloud gateway in a hub VPC using a Cisco Cloud OnRamp for Multicloud deployment. Which approach lets the branches consume the partner's application while keeping the traffic off the public internet?

Reviewed for accuracy · Report an issue
Question 14 of 25

An engineer connects an on-premises Cisco IOS XE router to a Cisco IOS XE router hosted in Azure over an IPsec VPN using a route-based (VTI) tunnel. The on-premises site runs OSPF internally, while eBGP is used across the IPsec tunnel to the cloud router to exchange prefixes. The engineer redistributes BGP-learned cloud prefixes into the on-premises OSPF process. After the change, internal OSPF routers receive the cloud prefixes but users report that traffic to the cloud is intermittently blackholed when a second, less-preferred WAN path also injects the same prefixes. What is the most effective way to ensure the OSPF-redistributed cloud routes are correctly and consistently preferred?

Reviewed for accuracy · Report an issue
Question 15 of 25

An engineer troubleshoots a route-based IPsec tunnel from a Cisco IOS XE router to a native Azure VPN gateway. The IOS XE router sits behind a corporate firewall that performs PAT (NAT overload) on its public interface. IKEv2 negotiation begins but never completes; 'show crypto ikev2 sa' shows the SA stuck in the IN-NEG state, and debugs show the Azure gateway is not authenticating the peer. The pre-shared keys, transform sets, and DH groups all match. What is the MOST likely cause?

Reviewed for accuracy · Report an issue
Question 16 of 25

An engineer configures a redundant design where an on-premises Cisco IOS XE router forms IPsec VTI tunnels to two AWS VGWs in separate regions. Both regions are interconnected, and AWS re-advertises the on-premises prefixes learned from one region toward the other. The IOS XE router logs no errors, tunnels are up, and BGP is established on both tunnels, but the router refuses to install the prefixes AWS advertises from the second region. 'show ip bgp' shows those prefixes received but with the reason 'received-only'. What is the most likely cause?

Reviewed for accuracy · Report an issue
Question 17 of 25

An engineer configures a Cisco IOS XE router as a route reflector for two internal iBGP peers (branch routers) while also maintaining an IPsec VTI eBGP session to an AWS Virtual Private Gateway. The AWS-learned VPC prefixes appear in the route reflector's BGP table as best paths, but the two iBGP branch peers install the AWS prefixes with an unreachable next hop and the routes fail to enter their RIB. The eBGP session to AWS is stable and the tunnel is up. What is the most likely cause?

Reviewed for accuracy · Report an issue
Question 18 of 25

An engineer configured a redundant IPsec VTI design between a Cisco IOS XE router and two AWS VPN tunnels toward a Transit Gateway. eBGP sessions to both AWS tunnel inside addresses come up and routes are learned. However, traffic destined to the VPC subnets is intermittently blackholed. On IOS XE, 'show ip route' shows the VPC prefixes as BGP routes whose next-hop is the AWS tunnel inside IP, but that next-hop is resolved via the default route pointing to the physical internet interface rather than the tunnel interface. What is the most likely cause of the blackholing?

Reviewed for accuracy · Report an issue
Question 19 of 25

An engineer manages an IPsec VTI tunnel from a Cisco IOS XE router to an AWS VPN gateway with eBGP over the tunnel. The tunnel interface is stable, but the AWS-learned prefixes for a specific VPC (10.50.0.0/16) intermittently disappear from the IOS XE routing table for several minutes at a time, then reappear. Other prefixes learned over the same BGP session remain stable throughout. 'show ip bgp 10.50.0.0/16' during the outage shows the path exists but is marked as 'dampened' with an accumulated penalty. What is the most likely cause?

Reviewed for accuracy · Report an issue
Question 20 of 25

An engineer builds a route-based IPsec VTI tunnel between an on-premises Cisco IOS XE router and an AWS cloud-hosted Cisco IOS XE router across the internet. The tunnel establishes successfully and passes traffic, but every few hours users report a brief drop of about 20-30 seconds, after which connectivity restores by itself. Debugs on the on-premises router show IKEv2 CHILD_SA re-creation events coinciding with the outages, and the two routers are configured with different IPsec SA lifetimes (on-prem 3600 seconds, AWS side 28800 seconds). What is the MOST likely cause of the periodic outage, and what corrective action addresses it?

Reviewed for accuracy · Report an issue
Question 21 of 25

An engineer configured a route-based IPsec VTI tunnel from an on-premises Cisco IOS XE router to an AWS VPN gateway. IKEv2 Phase 1 completes successfully and the SA is established, but no Phase 2 IPsec SA forms and 'show crypto ipsec sa' shows zero encrypted/decrypted packets. Debug output on the router shows 'ts_unacceptable' notifications received from AWS. What is the most likely cause?

Reviewed for accuracy · Report an issue
Question 22 of 25

An engineer connects an on-premises Cisco IOS XE router to an Azure VNet using two IPsec VTI tunnels to a route-based Azure VPN Gateway, both running BGP. Azure is advertising the same VNet prefix (10.50.0.0/16) over both tunnels, and the on-premises router is load-sharing return traffic across both. The requirement is that Tunnel1 be the primary path for all traffic destined to Azure, with Tunnel2 used only if Tunnel1 fails. Which action on the Cisco IOS XE router achieves deterministic primary/backup path selection for traffic sent TO Azure?

Reviewed for accuracy · Report an issue
Question 23 of 25

An engineer maintains an IPsec VTI tunnel from a Cisco IOS XE router to an Azure VPN gateway with eBGP over the tunnel. During brief, sub-second control-plane restarts on the IOS XE router (SSO switchovers on a dual-RP chassis), branch users report short traffic drops even though the tunnel interface never goes down. The Azure gateway supports BGP graceful restart. What should the engineer verify or configure on the IOS XE router to preserve forwarding across these restarts?

Reviewed for accuracy · Report an issue
Question 24 of 25

A network engineer has built two IPsec VTI tunnels from an on-premises Cisco IOS XE router to a single Azure VPN Gateway (active-active) and established eBGP over both tunnels. The on-premises router advertises the same on-prem prefix 10.10.0.0/16 over both tunnels. Azure is load-balancing return traffic across both tunnels, but the engineer wants Azure to prefer Tunnel 1 for all return traffic to 10.10.0.0/16, keeping Tunnel 2 purely as backup. Which action on the IOS XE router achieves this influence over Azure's inbound path selection?

Reviewed for accuracy · Report an issue
Question 25 of 25

An engineer manages a route-based IPsec VTI tunnel from an on-premises Cisco IOS XE router to an Azure VPN Gateway. The tunnel came up successfully, but after several hours users report intermittent loss of connectivity to Azure workloads. On the IOS XE router, 'show crypto ikev2 sa' shows the SA state flapping between READY and DELETING, and the logs contain repeated 'IKEv2-ERROR: Received INVALID_SPI notify' messages. Ping traffic recovers only after a manual 'clear crypto ikev2 sa'. What is the MOST likely cause of this behavior?

Reviewed for accuracy · Report an issue