Architecture Models
Drill 20 practice questions focused entirely on Architecture Models for the Cisco 300-440 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A financial services company already has a 10 Gbps AWS Direct Connect dedicated connection terminating at a colocation facility. The network team now needs to give an internal analytics application private, low-latency access to a third-party market-data SaaS offering that is published through AWS PrivateLink in a provider VPC. The traffic must never traverse the public internet, and the team wants to avoid provisioning a second physical circuit. Which approach lets them consume this SaaS service over their existing Direct Connect?
A financial services company runs a data-analytics application in an on-premises data center connected to AWS via an existing Direct Connect private VIF and a Direct Connect gateway. The security team mandates that traffic to Amazon S3 for storing regulatory reports must never traverse the public internet and must not require adding public IP prefixes to the Direct Connect public VIF. Which AWS connectivity construct should the network architect deploy to reach the S3 service privately over the existing private connectivity?
A financial services company already has an Azure ExpressRoute circuit terminating at a partner colocation facility. They now need to reach Microsoft 365 and Azure PaaS services (such as Azure Storage public endpoints) over their private ExpressRoute connection instead of the internet, while still using their existing IaaS VNet peering. The network team must configure the correct peering type for the SaaS and PaaS traffic. Which ExpressRoute peering type should be enabled to carry the Microsoft 365 and Azure public-service traffic?
A retail company operates 45 branch sites and wants to connect them to workloads hosted in three Azure regions. They need centralized, hub-based routing and automated any-to-any branch connectivity over the public internet without provisioning a dedicated private circuit. Cost sensitivity is high, and they want Microsoft to manage the underlying transit infrastructure. Which internet-based connectivity approach best meets these requirements?
A financial services company runs a critical third-party SaaS application that is published by the vendor as an Azure Private Link service. Security policy mandates that all traffic to this SaaS application must traverse the company's existing ExpressRoute private peering circuit and must never be exposed to the public internet, and the application must be reachable using a private IP address inside the company's Azure VNet. Which connectivity approach meets these requirements?
A financial services company runs its data analytics platform in Google Cloud and consumes BigQuery and Cloud Storage as managed SaaS-like services. Compliance rules prohibit any of this traffic from traversing the public internet, and the security team requires that the Google APIs be reached over the private/restricted Google API VIP range (not the public internet) from the on-premises data center over an existing Dedicated Interconnect. Which Google Cloud feature should the network architect configure to meet these requirements?
A retail company is deploying new branch sites that need connectivity to workloads hosted in Google Cloud. The company wants to avoid the cost and lead time of provisioning dedicated circuits, but still requires encrypted transport and dynamic routing between the branches and the cloud VPC. Which internet-based connectivity approach best meets these requirements?
A retail company is deploying a new branch-to-cloud design to reach workloads hosted in a Google Cloud VPC. The network team must use the existing public internet circuits (no dedicated physical cross-connect is budgeted this quarter), but the design must survive the failure of a single Google-side tunnel endpoint and provide a Google-backed availability SLA. Which internet-based connectivity approach to Google Cloud best meets these requirements?
A retail company is deploying a new branch-heavy architecture and wants to connect 30 branch sites to workloads running across multiple VPCs in a single AWS region. The networking team requires internet-based connectivity (no dedicated circuit budget), centralized route management across all VPCs, and encrypted transport. Which AWS connectivity approach best meets these requirements?
A retail company hosts its inventory microservices on Cisco Catalyst SD-WAN branch routers that must reach an application published in a partner's AWS VPC. The partner exposes the application only through an AWS PrivateLink endpoint service and will not accept traffic over the public internet. The company already terminates its cloud gateway in a hub VPC using a Cisco Cloud OnRamp for Multicloud deployment. Which approach lets the branches consume the partner's application while keeping the traffic off the public internet?
A financial services company has AWS VPCs deployed in us-east-1 and eu-west-1. They already have a single AWS Direct Connect connection terminating at a colocation facility in Virginia. The network team wants both regions' VPCs to be reachable over this existing physical Direct Connect connection without deploying additional cross-connects or public internet transit. Which AWS construct enables this multi-region private reachability over the single Direct Connect connection?
A financial services company is migrating a latency-sensitive trading application to AWS. The security team mandates that traffic to the VPC must never traverse the public internet, and the network team requires a dedicated, predictable bandwidth of 10 Gbps with a consistent SLA. The application also needs to reach resources in multiple VPCs across two AWS Regions. Which connectivity approach best satisfies these requirements?
A retail company uses Azure ExpressRoute for private connectivity to their IaaS workloads hosted in Azure virtual networks. The networking team now wants to extend the same ExpressRoute circuit to reach Microsoft 365 (a SaaS offering) over the private connection rather than the internet. Which ExpressRoute peering configuration must the team enable to support connectivity to the Microsoft 365 SaaS services?
A financial services company is migrating latency-sensitive trading applications to Microsoft Azure. Their compliance policy prohibits any application traffic from traversing the public internet, and they require a consistent, predictable SLA-backed bandwidth of 10 Gbps between their on-premises data center and Azure region. Which connectivity option should the network architect recommend?
A financial services enterprise is deploying a Cisco SD-WAN fabric and needs private connectivity from its on-premises data center to workloads running in Microsoft Azure. Compliance rules prohibit any of this traffic from traversing the public internet. The network team has provisioned an Azure ExpressRoute circuit and now must configure the correct routing domain (peering type) so that traffic destined for their Azure virtual networks stays private. Which ExpressRoute peering type should they configure for reaching resources inside their Azure VNets?
A financial services company runs latency-sensitive trading analytics in a Google Cloud VPC. They need a dedicated, physically isolated Layer 2 connection from their on-premises data center that provides 10-Gbps capacity with an SLA, and they can meet Google at a colocation facility. Which Google Cloud connectivity option should the network architect choose?
A financial services company is migrating a latency-sensitive analytics workload to Google Cloud. The architecture team requires a dedicated, private Layer 2/Layer 3 connection directly between their on-premises data center and Google's network, bypassing the public internet entirely, with committed bandwidth of 10 Gbps and a private SLA. Their data center is located in a facility that is a Google-supported colocation site. Which Google Cloud connectivity option best meets these requirements?
A retail company runs latency-sensitive inventory workloads in Google Cloud and cannot meet the co-location requirements of a dedicated 10-Gbps interconnect because their nearest data center is 200 km from any Google Cloud colocation facility. They need private (non-internet) Layer 3 connectivity with committed bandwidth of 5 Gbps and want to reuse an existing service provider relationship. Which Google Cloud private connectivity option best fits these constraints?
A retail company is deploying Amazon WorkSpaces (a SaaS desktop-as-a-service offering) for 400 remote agents. The network team wants the streaming traffic (PCoIP/WSP) to reach the AWS WorkSpaces service endpoints with the lowest latency and without backhauling user sessions through the on-premises data center. There is no requirement for a private, dedicated circuit. Which connectivity approach best meets these SaaS access requirements?
A retail company with 40 branch sites uses Google Workspace (Gmail, Drive, Meet) as its primary SaaS productivity suite. Users at branches report slow file uploads and choppy video calls when all SaaS traffic is backhauled over MPLS to a central data center before reaching the internet. The network team wants an architecture that improves the user experience for this Google SaaS traffic while keeping security policy enforcement. Which approach best meets the requirement?
More 300-440 practice
Keep going with the other Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) domains, or take a full timed mock exam.
← Back to 300-440 overview