Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) · Domain 4 · 25% of exam

SD-WAN Cloud Connectivity

Drill 20 practice questions focused entirely on SD-WAN Cloud Connectivity for the Cisco 300-440 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A network engineer is configuring Cisco Catalyst SD-WAN application-aware routing for a branch that has two transport tunnels: a low-latency MPLS (color 'mpls') and a broadband internet link (color 'biz-internet'). Business requirement: interactive video traffic must always prefer the MPLS tunnel, but if MPLS violates the SLA class (loss > 2%, latency > 150 ms), traffic should immediately move to biz-internet. If both tunnels violate the SLA, traffic must continue to flow rather than be dropped. Which application-aware route policy configuration meets all requirements?

Reviewed for accuracy · Report an issue
Question 2 of 20

A network architect is designing a Cisco Catalyst SD-WAN control policy so that branch sites in the East region prefer to reach data center services through the primary DC WAN edge (TLOC color 'mpls') and fall back to the secondary DC WAN edge (TLOC color 'biz-internet') only if the primary is unavailable. This preference must be enforced from vSmart without altering each branch's local configuration. Which approach correctly implements this requirement?

Reviewed for accuracy · Report an issue
Question 3 of 20

A network administrator manages a Cisco Catalyst SD-WAN fabric with 200 branch sites. The security team requires that only sites in the 'PCI-Scope' site-list be permitted to participate in VPN 40 (the cardholder data segment), while all other sites must not receive any VPN 40 routes or establish reachability into that segment. The administrator wants to enforce this restriction from vManage in a single centralized construct applied at the vSmart controllers. Which centralized policy component should be configured to achieve this requirement?

Reviewed for accuracy · Report an issue
Question 4 of 20

A network administrator is building a centralized data policy in Cisco Catalyst SD-WAN Manager to redirect specific application traffic from branch VPN 10 toward a data center service. During validation, the administrator notices the policy is not taking effect on traffic sourced from the branch LAN. The policy sequence, match conditions, and action are all confirmed correct. Which configuration element is most likely missing or misapplied that would cause the branch-originated traffic to be ignored by the centralized data policy?

Reviewed for accuracy · Report an issue
Question 5 of 20

A network architect is deploying Cisco Catalyst SD-WAN Cloud OnRamp for Multicloud to connect several branch sites to workloads running in AWS. The branches are grouped by geography, and each geographic group must reach the closest AWS region's host VPCs with the lowest possible latency. In the Cloud OnRamp workflow, which construct is used to associate specific branch VPN segments and their sites with the cloud gateway serving a chosen AWS region?

Reviewed for accuracy · Report an issue
Question 6 of 20

A network architect is designing Cisco Catalyst SD-WAN Cloud OnRamp for Multicloud into AWS. The organization already has 12 existing application VPCs that must remain unchanged, and they want SD-WAN cloud gateways deployed so that all 12 VPCs connect through a shared attachment point managed by AWS, with the cloud gateways peering to that attachment via BGP. Which OnRamp deployment component must the architect configure to meet these requirements?

Reviewed for accuracy · Report an issue
Question 7 of 20

A network architect is deploying Cisco Catalyst SD-WAN Cloud OnRamp for Multicloud to connect branch WAN Edge routers to workloads in an AWS host VPC. The design requires that if the primary transit region's Cloud Gateway fails, branch traffic to the cloud workloads must continue over an alternate path without manual intervention, and both Cloud Gateway WAN Edge instances must appear as valid next hops in the SD-WAN overlay. Which deployment approach satisfies these resiliency requirements?

Reviewed for accuracy · Report an issue
Question 8 of 20

A network engineer is deploying Cisco Catalyst SD-WAN Cloud OnRamp for Multicloud into an AWS environment. The design requires the SD-WAN cloud gateway (Catalyst 8000V instances in a transit VPC) to exchange routes dynamically with an existing AWS Transit Gateway so that branch prefixes are learned by multiple spoke VPCs, and TGW-attached VPC prefixes are advertised back into the SD-WAN overlay. Which attachment and routing mechanism should the engineer configure between the cloud gateway and the Transit Gateway to meet this requirement?

Reviewed for accuracy · Report an issue
Question 9 of 20

A network engineer is deploying Cisco Catalyst SD-WAN Cloud OnRamp for Multicloud into AWS. The design must connect multiple SD-WAN branch sites to workload VPCs across two AWS regions, while allowing the SD-WAN cloud gateway capacity to grow automatically as branch throughput increases without manual instance provisioning. Which configuration approach in vManage/Cloud OnRamp best meets these requirements?

Reviewed for accuracy · Report an issue
Question 10 of 20

A network engineer enables Cisco Catalyst SD-WAN Cloud OnRamp for SaaS to optimize access to a monitored cloud application at a branch site that has both a Direct Internet Access (DIA) circuit and a tunnel back to a regional gateway. After configuration, the engineer wants SD-WAN to automatically pick the path with the best application experience. Which mechanism does Cloud OnRamp for SaaS use to determine which egress path delivers the best experience for the SaaS application?

Reviewed for accuracy · Report an issue
Question 11 of 20

A network engineer is enabling Cisco Catalyst SD-WAN Cloud OnRamp for SaaS to optimize Office 365 traffic for a remote branch. The branch has a local Direct Internet Access (DIA) circuit, but the SD-WAN administrator wants OnRamp to measure application performance and automatically steer the SaaS traffic over the best-performing path, which may be either the local DIA or a Cloud Gateway site. Which OnRamp configuration element must be defined so that a branch without a qualifying local exit can still forward SaaS traffic through a regional data center or cloud gateway that hosts the internet exit?

Reviewed for accuracy · Report an issue
Question 12 of 20

A network administrator has enabled Cisco Catalyst SD-WAN Cloud OnRamp for SaaS to optimize Microsoft 365 traffic across two branch sites, each with a DIA circuit and an MPLS path back to a gateway site. After configuration, the administrator notices that traffic is not being steered to the best-performing path and neither interface shows any differentiated probe measurements (both display the default vQoE indicator) for the M365 application. What is the most likely cause of this behavior?

Reviewed for accuracy · Report an issue
Question 13 of 20

A network engineer enables Cloud OnRamp for SaaS on two branch WAN Edge routers, each configured with a Direct Internet Access (DIA) exit through its local ISP. Users at the branch report intermittent session drops when accessing a cloud SaaS application. Investigation shows that outbound SaaS traffic can leave through either of the two DIA interfaces depending on the best-performing path, but return traffic sometimes arrives on the opposite interface, breaking stateful NAT translations. Which configuration action best resolves the asymmetric-flow problem while preserving OnRamp for SaaS path optimization?

Reviewed for accuracy · Report an issue
Question 14 of 20

A network engineer is enabling Cloud OnRamp for SaaS on a branch WAN Edge router that has two Direct Internet Access (DIA) transport interfaces. The engineer wants Cisco Catalyst SD-WAN Manager to continuously evaluate the quality of each internet path to a monitored SaaS application and automatically steer application traffic out the interface with the best experience. Which mechanism does Cloud OnRamp for SaaS use on the WAN Edge to make this per-application path decision?

Reviewed for accuracy · Report an issue
Question 15 of 20

A company is deploying Cisco Catalyst SD-WAN Cloud OnRamp for SaaS to optimize access to a cloud-hosted collaboration application. The network administrator enables the SaaS application in the OnRamp configuration and assigns two candidate WAN interfaces at each branch: a Direct Internet Access (DIA) circuit and a gateway path through a regional cloud gateway site. After deployment, users at a branch report suboptimal performance even though both paths are up. The administrator confirms Cloud OnRamp for SaaS is enabled but suspects the traffic is not being steered based on real-time application experience. Which mechanism does Cloud OnRamp for SaaS use to determine and continuously steer traffic to the best-performing path for the SaaS application?

Reviewed for accuracy · Report an issue
Question 16 of 20

A network engineer is deploying Cisco Catalyst SD-WAN Cloud OnRamp for SaaS in a design that uses a regional cloud gateway. Branch sites in Europe have their SaaS traffic for a monitored application steered through a gateway hosted in a US region because that gateway was configured first and was the only eligible gateway mapped at the moment of onboarding. Users report high latency. The engineer needs the branches to select the geographically closest gateway going forward while keeping automatic quality-based failover. Which action best resolves the suboptimal path selection?

Reviewed for accuracy · Report an issue
Question 17 of 20

A network engineer is enabling Cisco Catalyst SD-WAN Cloud OnRamp for SaaS across an enterprise fleet. Branch sites in VPN 10 host users who access Microsoft 365 and should be steered through Direct Internet Access (DIA) exits, while a regional hub site is configured as a gateway to provide SaaS optimization for VPN 10 branches that lack a qualifying local internet exit. When configuring the Cloud OnRamp for SaaS application list in vManage, which action must the engineer take so that the intended sites and traffic are correctly evaluated for the best-path selection?

Reviewed for accuracy · Report an issue
Question 18 of 20

A retail enterprise runs Cisco Catalyst SD-WAN Cloud OnRamp for SaaS to optimize Salesforce and Microsoft 365 traffic. Branch sites use two transport interfaces: a primary MPLS color (mpls) and a secondary broadband color (biz-internet). The network team wants SaaS application probing to select the best-performing path per application, but they discover that when Cloud OnRamp for SaaS is enabled, SaaS traffic can only be optimized over gateways or DIA-capable interfaces that meet a specific requirement. Which requirement must the branch's biz-internet interface satisfy so it can serve as a Direct Internet Access exit for the SaaS application probes?

Reviewed for accuracy · Report an issue
Question 19 of 20

A retail chain runs Cisco Catalyst SD-WAN across 200 branch sites. Each branch has a single low-bandwidth broadband circuit terminated on a cEdge. The network team wants to optimize Webex (a SaaS application) performance for these branches. The branches have no local Cloud OnRamp gateway, and adding regional gateways for all branches is not budgeted. The team wants Webex traffic to break out to the internet as close to the user as possible while still measuring application loss/latency and choosing the best available path. Which Cloud OnRamp for SaaS deployment approach best fits these branch sites?

Reviewed for accuracy · Report an issue
Question 20 of 20

A retail enterprise uses Cisco Catalyst SD-WAN Cloud OnRamp for SaaS to optimize Webex traffic for 40 branch sites. Each branch has two DIA transport links (biz-internet and public-internet). During peak business hours, users at several branches report jitter and audio dropouts, and the network team confirms that Webex traffic keeps traversing the biz-internet link even after its packet loss rises above acceptable levels. Cloud OnRamp for SaaS is already enabled with application probing on both interfaces. What is the MOST likely cause that prevents automatic rerouting to the better-performing path?

Reviewed for accuracy · Report an issue

More 300-440 practice

Keep going with the other Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) domains, or take a full timed mock exam.

← Back to 300-440 overview