🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)92 / 128
Question 92 of 128

A network administrator manages a Cisco Catalyst SD-WAN fabric with 200 branch sites. The security team requires that only sites in the 'PCI-Scope' site-list be permitted to participate in VPN 40 (the cardholder data segment), while all other sites must not receive any VPN 40 routes or establish reachability into that segment. The administrator wants to enforce this restriction from vManage in a single centralized construct applied at the vSmart controllers. Which centralized policy component should be configured to achieve this requirement?

Reviewed for accuracy · Report an issueNext question