Design
Drill 15 practice questions focused entirely on Design for the Cisco 300-440 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A financial services company must connect its on-premises data center to AWS using a dedicated private circuit. A security requirement states that all data traversing the Layer 2 link between the customer premises and the AWS Direct Connect location must be encrypted at line rate without adding routing overhead or reducing throughput. The design team wants to satisfy this at the physical link layer rather than relying on an IPsec tunnel over the connection. Which capability should the design recommend?
A financial services company hosts a customer-facing web application in an AWS VPC. Security requires that all inbound connections from the internet must terminate at a managed edge that provides DDoS protection and web application filtering before traffic reaches the application subnets. The team also wants to avoid exposing EC2 instances with public IP addresses. Which cloud security design for inbound connectivity best meets these requirements?
A retail enterprise runs several application VPCs in AWS behind a Transit Gateway. Security policy requires that all outbound internet traffic from these workloads be centrally inspected for threats and logged before leaving AWS, with no workload allowed to reach the internet through its own path. Which cloud security design should the network architect recommend for the outbound (backhaul) internet traffic?
A global manufacturing firm hosts several VMs in an Azure VNet. Corporate security policy mandates that ALL outbound internet traffic from cloud workloads be inspected by the on-premises next-generation firewall stack before reaching the internet, with full logging for audit. The firm already has redundant ExpressRoute circuits to the on-premises data center. Which connectivity design should the network architect recommend to enforce this backhaul internet inspection requirement?
A financial services company is migrating a latency-sensitive trading analytics workload to Azure. Requirements include: a consistent 5 Gbps of throughput, BGP-based dynamic routing between on-premises and Azure, redundancy across two physically diverse paths at the peering location, and the ability to advertise the same on-premises prefixes over both paths for active/active load distribution. Which connectivity design best satisfies these network architecture requirements?
A financial services company is migrating a latency-sensitive trading analytics platform to Microsoft Azure. The business requires a connectivity model that provides a contractual uptime guarantee, predictable low latency, and no dependency on the public internet. The network team already has a partner presence in a carrier-neutral colocation facility that offers Layer 2 connections to Azure peering locations. Which connectivity model should the architect recommend to best meet these requirements?
A financial services company is deploying a multi-tier application across several Azure virtual networks (VNets) in a hub-and-spoke topology. Compliance auditors require that lateral (east/west) traffic between the web, application, and database tiers be inspected and filtered by a stateful firewall, and that no tier can communicate directly without policy enforcement. The security team wants to centralize this inspection with minimal per-VNet configuration. Which design best meets these requirements?
A U.S. federal agency contractor is migrating a sensitive workload to AWS GovCloud. Compliance mandates that the workload meet FedRAMP High requirements, and that all data in transit between the on-premises data center and the cloud must never traverse the public internet. The security team also requires that connectivity avoid shared transport infrastructure to reduce the risk of data commingling with other tenants. Which connectivity model should the network architect recommend?
A financial services company runs multiple workloads in Google Cloud across several VPCs. Security policy mandates that all outbound internet-bound traffic from these workloads must be centrally inspected by a next-generation firewall for logging, threat prevention, and URL filtering before leaving the cloud. The design team wants to avoid each VPC egressing directly to the internet. Which connectivity/security design best meets this backhaul internet traffic requirement?
A financial services company hosts a customer-facing web application in Google Cloud. Security requires that all inbound connections from the internet must terminate on a managed edge service that provides DDoS protection, TLS offload, and Layer 7 WAF filtering before traffic reaches backend VM instances. The backend instances must not have public IP addresses. Which connectivity and security design for inbound traffic best meets these requirements?
A mid-sized retail company is designing private connectivity from its on-premises data center to Google Cloud. Their analysis shows steady-state throughput of about 3 Gbps to VPCs, with occasional bursts. They do not have a physical presence in any Google colocation facility and want to avoid the cost and lead time of provisioning cross-connects in a Google peering location. Availability targets are moderate (99.9%), and they prefer to onboard within a few weeks. Which connectivity model should you recommend?
A retail company hosts a fleet of backend processing VMs in a private subnet within a Google Cloud VPC. These VMs have no external IP addresses but must initiate outbound calls to a third-party payment API over the public internet. The security team mandates that no inbound internet connections be permitted to these VMs. Which Google Cloud service should the network architect deploy to meet these requirements?
A US federal contractor must connect its on-premises data center to workloads in AWS and Azure. The security team requires alignment with NIST SP 800-53 controls, specifically continuous data-in-transit protection (SC-8/SC-13) across all cloud links, even over dedicated private circuits. The network team notes that both AWS Direct Connect and Azure ExpressRoute are being deployed via a colocation provider. Which connectivity design recommendation best satisfies the NIST data-in-transit requirement?
A retail company must extend its on-premises PCI DSS cardholder data environment (CDE) to an AWS region hosting a payment processing application. Regulatory auditors require that cardholder data in transit never traverse the public internet, that the link provide predictable, dedicated bandwidth for consistent transaction latency, and that all traffic be encrypted end-to-end. The company already has a colocation presence at a carrier-neutral facility where AWS offers a physical cross-connect. Which connectivity model best satisfies these requirements?
A multinational financial services firm must connect its on-premises data center to workloads hosted in a public cloud region. The security and compliance team mandates that all cloud connectivity align with ISO/IEC 27001 controls, specifically ensuring that customer data in transit is never exposed to the public internet and that the connection provides auditable, predictable, and consistent performance for regulator reporting. Cost is a secondary concern relative to compliance and traceability. Which connectivity model should the network architect recommend?
More 300-440 practice
Keep going with the other Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) domains, or take a full timed mock exam.
← Back to 300-440 overview