How to find: Press "Ctrl + F" in your browser and type key terms to locate the specific exam item or explanation. If the item is not listed on this page, please search for it in our comprehensive IT Exam Items Repository.
Modules 23 - 26: Checkpoint Exam: Software-Defined Networking Answers (CCNP ENCOR v9)
1. Which feature of Cisco Catalyst Center helps in the definition of user and device profiles that facilitate highly secure access and network segmentation based on business needs?
- policy
- platform
- security
- provision
Explanation: Topic 23.3.0
Cisco Catalyst Center is composed of several core functional areas designed to automate and secure network operations. The policy component is specifically responsible for defining user and device profiles that facilitate highly secure access and network segmentation tailored to business needs. This feature supports group-based policies and segmentation to ensure consistent security enforcement across the infrastructure. Other primary components include Design for maps and topologies, Provisioning for automated service delivery, and Assurance for proactive network monitoring and optimization.
2. Which of these is the correct URL format to issue a REST API call to Cisco Catalyst SD-WAN Manager that retrieves a list of all devices in the network?
- http://manager_ip/dataservice/device
- https://manager_ip/device
- https://manager_ip/dataservice/device
- http://manager_ip/device
Explanation: Topic 26.6.3
The Cisco Catalyst SD-WAN Manager web server uses HTTPS as its primary communications protocol for REST API calls. To retrieve inventory data, such as a list of devices in the network, a GET request must be issued to the specific resource path /dataservice/device. Therefore, the correct full URL format is https://manager_ip/dataservice/device. The sources also note that before this call can be successful, the user must first authenticate (typically via the /j_security_check resource) to obtain a session cookie.
3. Which Cisco Catalyst Center API retrieves site hierarchy with network health information?
- Client Health Intent API
- Network Device Detail Intent API
- Site Hierarchy Intent API
- Network Health Intent API
Explanation: Topic 26.5.2
The Know Your Network API domain is organized into several subdomains. The Topology subdomain is specifically used to retrieve network health information and site and network physical, Layer 2, Layer 3, and VLAN information. In Cisco Catalyst Center, this functionality is provided by the Network Health Intent API, which allows for viewing the status of the network across the site hierarchy.
The other options listed serve different functions:
- Client Health Intent API: Returns overall client health information organized into wired and wireless categories.
- Network Device Detail Intent API: Retrieves detailed information about specific devices (such as configuration, interfaces, and modules) based on MAC address, UUID, or name.
- Sites Subdomain: While it allows administrators to obtain site information and manage hierarchical collections of sites and buildings, it is not primarily described as the source for combined health metrics in the way the Topology/Network Health API is.
4. Which option is a centralized CLI management tool to help design and provision templates in the Cisco Catalyst Center?
- Image Repository
- CLI Template
- CLI Edit tool
- USB flash storage
Explanation: Topic 23.4.11
CLI Templates is defined in the sources as a centralized CLI management tool provided by Cisco Catalyst Center. It features an interactive editor that allows network operators to design, build, and provision generic configurations for one or more devices within a specific site. The tool supports various functions, including creating, editing, and deleting templates, as well as validating them for errors and simulating them before deployment. These templates can utilize variables and interactive commands to automate repetitive configuration tasks efficiently.
5. Which Cisco Catalyst Center tool enables you to perform CRUD operations on templates and projects that the template programmer uses to facilitate design and provisioning workflows in Cisco Catalyst Center?
- Command Runner API
- Template Programmer API
- Path Trace API
- Task API
Explanation: Topic 26.5.2
The Template Programmer API (associated with the Configuration Templates subdomain) is a centralized CLI-management tool used to facilitate design and provisioning workflows within Cisco Catalyst Center. This specific API enables users to perform CRUD operations—allowing them to create, view (read), edit (update), and delete both templates and projects.
The other options serve different purposes:
- Command Runner API: Used to retrieve CLI keywords and run read-only commands on devices to check real-time configuration.
- Path Trace API: Used to trace application paths and provide hop-by-hop statistics to resolve performance issues.
- Task API: Used to query the status of asynchronous actions to determine if a request completed successfully.
6. Which three options are examples of an overlay network? (Choose three.)
- IPv4
- LISP
- MPLS
- RIPv2
- IPX
- CAPWAP
Explanation: Topic 24.3.1
An overlay network is defined as a logical topology used to virtually connect devices that is built on top of an arbitrary physical underlay topology. According to the sources, common examples of overlay networks include Multiprotocol Label Switching (MPLS), Locator/ID Separation Protocol (LISP), and Control and Provisioning of Wireless Access Points (CAPWAP).
- LISP is utilized in the Cisco SD-Access fabric as the control plane to decouple an endpoint's identity from its location.
- MPLS is a mechanism used to create Layer 3 VPNs and provide path isolation over shared physical infrastructure.
- CAPWAP functions as a network overlay by forming a tunnel between an Access Point and a Wireless LAN Controller to transport all client traffic.
In contrast, IPv4 and IPX are typically referred to as "passenger protocols" that are encapsulated by these overlays, and RIPv2 is a traditional routing protocol.
7. Which Cisco SD-WAN component has programmatic interfaces to enable DevOps operations and to also extract performance statistics collected from the entire fabric?
- Cisco WAN Edge router
- Cisco vBond
- Cisco vSmart controller
- Cisco vManage
Explanation: Topic 25.5.0
The Cisco Catalyst SD-WAN Manager (vManage) is the central management plane component of the fabric, serving as a "single pane of glass" for Day 0, Day 1, and Day 2 operations. According to the sources, it provides programmatic interfaces (REST APIs) that allow users to enable DevOps operations, such as automated configuration changes and template management. Additionally, these interfaces are used to extract performance statistics collected from the entire fabric, which can then be exported to external systems or the Cisco Catalyst SD-WAN Analytics tool for deeper examination. While WAN Edge routers do export statistics, they send them to the Manager, which centralizes them for programmatic access.
8. What are three primary focus areas for Cisco Catalyst Center Assurance and Analytics? (Choose three.)
- licensing
- streaming telemetry
- end-to-end visibility
- automation
- endpoint predictability
- predict performance
Explanation: Topic 23.12.2
Cisco Catalyst Center Assurance and Analytics focus on transforming network operations through the following areas:
- streaming telemetry: The Assurance architecture is designed for real-time data collection and ingestion, leveraging streaming technologies (streaming telemetry) to collect a variety of network telemetry and contextual data. This telemetry allows the system to poll network devices and collect data according to settings for SNMP, syslogs, and NetFlow.
- end-to-end visibility: Assurance enables visibility of the entire network through multiple lenses, including geography, hierarchy, and topology. A key troubleshooting tool mentioned is Path Trace, which provides end-to-end visibility by following the path from any source to a destination device at the port level to resolve performance issues.
- predict performance: A major focus of AI-driven analytics is to reduce outages and minimize business impact using predictive performance analytics. The system uses proactive sensor testing to test protocol connectivity and performance to discover issues before they occur, effectively allowing the network to predict performance and behavior trends.
In contrast, automation is primarily categorized under the Provisioning functional area, and licensing is a prerequisite for using advanced features like AI Analytics rather than a focus area of the analytics engine itself.
9. Which node serves as the gateway between the fabric domain and the known network outside of the fabric?
- intermediate node
- fabric border node
- default border node
- border node
Explanation: Topic 24.4.4
Fabric border nodes serve as the gateway between the Cisco SD-Access fabric site and the networks external to the fabric. They are responsible for network virtualization interworking, advertisement of EID subnets (typically using BGP), and SGT propagation from the fabric to the rest of the network. These nodes can be configured in different roles: an internal border connects to a well-defined/known set of IP subnets (such as a data center or shared services), while an external border serves as the gateway of last resort for unknown destinations outside the enterprise.
10. Which Cisco SD-WAN component displays application performance for the last 24 hours with the vQoE of 0 to 10, with 0 as the worst performance and 10 as the best?
- Cisco WAN Edge router
- Cisco vManage
- Cisco vBond
- Cisco vAnalytics
Explanation: Topic 25.9.0
The Cisco Catalyst SD-WAN Analytics (vAnalytics) platform provides graphical representations of overlay network performance and includes a dashboard that serves as an interactive overview. This dashboard displays information covering the most recent 24 hours. Specifically, it tracks application performance using a QoE (Quality of Experience) score that ranges from 0 to 10, where 0 is the worst performance and 10 is the best. The platform calculates this score by analyzing telemetry data for latency, loss, and jitter, and it is customized for each specific application. While Cisco Catalyst SD-WAN Manager (vManage) extracts the performance statistics from the fabric, it exports them to the Analytics tool for this deeper level of processing and scoring.
11. Which Cisco SD-WAN component operates in the Management plane?
- Cisco vManage
- Cisco WAN Edge routers
- Cisco vBond
- Cisco vAnalytics
Explanation: Topic 25.5.0
The Cisco Catalyst SD-WAN Manager (vManage) is the primary component of the management plane and serves as a "single pane of glass" for Day 0, Day 1, and Day 2 network operations. Its core functions include centralized provisioning, standardization of configurations, and providing real-time alerting and visibility across the entire fabric. It also offers programmatic interfaces (REST APIs) that allow for DevOps automation and the extraction of performance statistics.
In contrast, other components operate in different planes:
- Cisco vBond (Cisco Catalyst SD-WAN Validator) operates in the orchestration plane.
- Cisco WAN Edge routers operate in the data plane.
- Cisco vSmart (Cisco Catalyst SD-WAN Controller) operates in the control plane.
- Cisco vAnalytics is an optional cloud-based analytics engine used for deeper processing of the telemetry data exported by the Manager.
12. Which server return code indicates that the server accepted your request, but it must perform other actions in order to complete the request?
- 200 OK
- 202 Accepted
- 201 Created
- 206 Partial Content
Explanation: Topic 26.3.1
The HTTP status code 202 (Accepted) indicates that the server accepted your request, but it must perform other actions in order to complete the request. For instance, if the Cisco Catalyst Center platform needs to interact with various network devices to fulfill a specific command, it will return this code.
In contrast, other codes serve different purposes:
- 200 (OK): Means the request succeeded and the response already includes the result of the action.
- 4xx codes: Indicate that the request failed due to a client-side error, such as a 401 (Unauthorized) code.
- 5xx codes: Indicate that the failure was due to a server-side error, such as a 503 (Service Unavailable) code.
13. Which node is part of the underlay network?
- edge node
- border node
- intermediate node
- control node
Explanation: Topic 24.4.0
The intermediate node is the node type that is part of the underlay network. While the campus fabric is composed of control plane, edge, border, and intermediate nodes, their functions differ between the underlay and overlay.
- Edge nodes, border nodes, and control plane nodes all have specific functional roles within the overlay network, such as endpoint registration, acting as a gateway to external networks, or maintaining the host tracking database.
- Intermediate nodes, by contrast, serve the underlay by providing IP reachability and connectivity between the other nodes in the fabric. As noted in the conversation history, they provide reachability within the fabric underlay but do not serve as external gateways or perform overlay-specific mapping functions.
The role of the underlay network is to establish physical connectivity using a routing protocol (typically IS-IS) to ensure packets can be delivered between fabric boundaries.
14. Which three options are limiting factors of traditional networks in the new age of digitalization? (Choose three.)
- IP Access Lists
- VRFs
- VLANs
- VXLANs
- IP subnets
- LISPs
Explanation: Topic 24.2.3
Traditional networks rely on topology-based constructs that have become limiting factors in the face of modern digitalization requirements, such as host mobility and large-scale automation.
- VLANs: The sources explicitly state that VLANs are a limiting factor due to inefficient use of available network links, rigid requirements on device placements, and limited scalability (restricted to 4,094 IDs).
- IP subnets: Traditional segmentation is tied to the network topology, such as the IP subnet, which limits flexibility because policies are coupled to where a device is physically located in the network.
- IP Access Lists: In traditional designs, security policies leverage ACLs that are statically mapped to IP and MAC addresses. The sources note that it is challenging to track ACLs, VLANs, and IP addresses to ensure optimal policy and security compliance as the network grows.
In contrast, VXLAN and LISP are modern overlay technologies used in Cisco SD-Access to overcome these traditional limitations. While VRFs are used in traditional segmentation, the primary "topology-based" constraints highlighted as hurdles for digitalization are VLANs, subnets, and the resulting complexity of ACL management.
15. What Cisco Catalyst Center tool provides visibility of what endpoints are there on the network and how they can be authenticated and assigned an appropriate policy for network usage, security, and segmentation?
- Cisco Umbrella
- Design
- Provision
- AI Endpoint Analytics
Explanation: Topic 23.5.0
AI Endpoint Analytics is the specific tool within Cisco Catalyst Center that provides visibility of what endpoints are on the network. Beyond simple identification, it helps determine how they can be authenticated and assigned an appropriate policy for network usage, security, and segmentation. This tool is part of the SecOps functional area, which focuses on eliminating vulnerabilities and ensuring the network remains secure through proactive scans and endpoint classification.
16. Which three tools have been upgraded to include network operations in their process? (Choose three.)
- BGP
- Chef
- Puppet
- Inventory
- RSTP
- Ansible
Explanation: Topic 23.4.0
Tools that were originally designed to help automate workflows for applications and cloud infrastructure, such as Ansible, Puppet, and Chef, have been upgraded to include network operations in their process. This integration of NetOps and DevOps concepts allows teams to use these tools to automatically make configuration changes and update network devices. While these tools began in the application and cloud sectors, they expanded their portfolios to include network automation after gaining significant traction in the industry.
17. Which Cisco Catalyst Center tool provides programmatic access to the discovery functionality of Cisco Catalyst Center?
- Template Programmer API
- Command Runner API
- Network Discovery API
- Path Trace API
Explanation: Topic 26.5.7
The Network Discovery API is the specific tool that provides programmatic access to the discovery functionality of Cisco Catalyst Center. It allows users to create, update, delete, and manage discovery jobs and their associated credentials, as well as retrieve the specific network devices that a particular discovery job acquired.
The other options in the query serve different operational purposes:
- Template Programmer API: Used for CRUD operations on configuration templates and projects.
- Command Runner API: Used to run read-only commands on network devices to retrieve real-time configuration.
- Path Trace API: Used to analyze and trace application flows between endpoints to resolve performance issues.
18. Which building block of the IBN includes functions that ensure that the derived model-based policies are disseminated throughout any of the relevant network domains?
- programmability
- activation
- translation
- assurance
Explanation: Topic 23.4.2
Activation is the principal functional building block of an Intent-Based Network (IBN) that includes functions to ensure that the derived model-based policies are disseminated throughout any of the relevant network domains. These domains can include the data center, WAN, branches, and campuses. The activation block also handles orchestration, allowing policies to be limited in scope to specific parts of the network, and may employ additional functions to derive appropriate device configurations using standards-based APIs like NETCONF or REST.
The other two primary building blocks described in the sources serve different roles:
- Translation: This block captures business intent and harmonizes it into a common model-based policy.
- Assurance: This block provides continuous verification and contextual analysis to ensure the network is delivering the desired outcomes.
19. In Cisco Catalyst Center, what are three server settings for network services that can be applied at a global level, which can then be inherited by all sites under the hierarchy? (Choose three.)
- DHCP
- XML
- AAA
- PTP
- TFTP
- NTP
- IRC
Explanation: Topic 23.4.5
In Cisco Catalyst Center, the Design application uses a hierarchical format that allows network operators to define common resources at a global level, which are then inherited by all child sites, buildings, and floors. This eliminates the need to manually redefine the same resources in multiple places. According to the sources, the three network services from your list that can be applied globally and inherited are:
- AAA: Used to perform network, client, and endpoint authentication via servers like Cisco ISE.
- DHCP: Defined as a standardized set of configuration parameters for the entire hierarchy.
- NTP: Configured to ensure all network infrastructure devices have synchronized time.
Other attributes that follow this global inheritance and site-specific override model include DNS servers, syslog servers, SNMP trap servers, and device credentials. While settings are inherited by default, they can be manually overridden at any specific site level to meet local requirements.
20. Which LISP infrastructure device stores registered EID prefixes in a mapping database where they are associated to RLOCs?
- map resolver
- proxy ETR
- proxy ITR
- map server
Explanation: Topic 24.5.3
A map server (MS) is the specific LISP infrastructure device to which Egress Tunnel Routers (ETRs) register their EID prefixes. Its primary function is to store these registered EID prefixes in a mapping database where they are associated with RLOCs. All LISP sites then utilize this mapping system to resolve EID-to-RLOC mappings for traffic forwarding.
In the context of a Cisco SD-Access fabric, this map server functionality is typically combined with map resolver (MR) duties on the control plane node, which manages the host tracking database (HTDB) to maintain these associations. In contrast, a map resolver is the device that receives queries from Ingress Tunnel Routers (ITRs) rather than storing the registrations itself.
21. Match the Cisco SD-WAN component with the fabric plane to which it belongs:

Explanation: Topic 25.3.0
| Management |
Cisco vManage |
| Orchestration |
Cisco vBond |
| Data |
Cisco WAN Edge |
| Control |
Cisco vSmart |
22. In Cisco Catalyst Center, which important principle helps to lower IT costs and complexity while meeting business and user expectations?
- analytics
- insights and actions
- security and compliance
- automation and assurance
Explanation: Topic 23.7.1
Cisco Catalyst Center is characterized as a complete network automation and assurance solution. These two principles are fundamental to its ability to lower IT costs and reduce complexity:
- Automation: By using features such as zero-touch provisioning (PnP) and Software Image Management (SWIM), the platform automates routine administrative and provisioning tasks, reducing device installation and upgrade times from hours to minutes. This policy-driven approach reduces the time spent on simple network operations and minimizes human error.
- Assurance: This function provides deep visibility and AI-driven insights into the health of the network, devices, and applications. It utilizes guided remediation and predictive analytics to resolve issues quickly, which increases network uptime and ensures that business and user expectations for a seamless experience are met.
Together, automation and assurance transform network operations from a reactive, manual process into an agile, proactive system that aligns the network with business intent.
23. Where does Cisco Catalyst Center store all the unique software images?
- external TFTP server
- Cisco Networking Design Center
- external FTP server
- Image Repository
Explanation: Topic 23.4.10
Cisco Catalyst Center manages software through a feature called Software Image Management (SWIM). The Image Repository is a specific part of the design application that serves as the central software storage for the system. Within this repository, Cisco Catalyst Center stores all of the software images, Software Maintenance Updates (SMUs), subpackages, and ROM monitor images for the various devices in your network.
The repository allows network operators to view, import, and delete images, as well as designate specific versions as "golden images" to ensure consistency and compliance across the organization. While administrators can configure up to three external image distribution servers (using protocols like SFTP) to assist in the distribution process for different geographical regions, the primary management and storage of these unique images reside within the internal Image Repository.
24. Which three options correctly define the features of Cisco Catalyst Center? (Choose three.)
- An open and extensible platform allows third-party applications and processes to exchange data.
- Zero-touch device provisioning and software image management.
- SAN and server provisioning and configuration management.
- User and device profiles that facilitate highly secure access and network segmentation based on business needs.
- Device and network RADIUS-based authentication services through third-party FTP services.
- Server profiles that limit access and avoid unnecessary network segmentation.
Explanation: Topic 23.2.1
Cisco Catalyst Center provides a comprehensive set of management, automation, and security features for enterprise networks:
- Open and Extensible Platform: The solution is designed as an open platform that utilizes northbound REST APIs and SDKs. This allows third-party applications and external systems (such as ITSM systems like ServiceNow or IPAM systems) to exchange data and intelligence, ensuring the network stays aligned with broader business processes.
- Zero-touch Provisioning and SWIM: Catalyst Center simplifies network operations through automation features like Plug-and-Play (PnP) for near zero-touch device deployment. It also includes Software Image Management (SWIM), which provides a central repository for software images and automates upgrades to ensure all devices run validated "golden images," reducing manual configuration time from hours to minutes.
- Secure Access and Segmentation: The platform's Policy component allows administrators to define user and device profiles that enforce highly secure access. It supports granular macro- and micro-segmentation to isolate traffic and limit the network's attack surface based on business intent, often integrating with Cisco Identity Services Engine (ISE) for identity-based control.
Other options, such as SAN provisioning or using FTP for RADIUS services, are not core functions of the Cisco Catalyst Center platform as described in the sources.
25. What are two benefits of VXLANs over the segmentation limiting factors of traditional VLANs? (Choose two.)
- better utilization of available network paths
- rigid requirements on device placement
- eliminates the use of multitenant segments within the data center
- inefficient use of available network links
- flexible placement of multitenant segments throughout the data center
Explanation: Topic 24.6.1
Traditional VLANs have several limiting factors in modern data centers, specifically the inefficient use of network links due to Spanning Tree Protocol (STP) and rigid requirements on device placement based on physical Layer 2 boundaries. VXLAN overcomes these issues through the following benefits:
- Better utilization of available network paths: Unlike traditional VLANs that use STP to block redundant paths to prevent loops, VXLAN encapsulates frames into Layer 3 UDP packets. This allows the network to take full advantage of Layer 3 routing features like Equal-Cost Multipath (ECMP) and link aggregation, utilizing all available paths in the fabric.
- Flexible placement of multitenant segments: VXLAN decouples the overlay network from the physical underlay, allowing Layer 2 segments to be extended over the Layer 3 infrastructure. This eliminates the traditional Layer 2 boundaries that forced rigid device placement, enabling multitenant segments to be placed anywhere throughout the data center.
Additionally, while VLANs are limited to 4,094 IDs, VXLAN supports up to 16 million coexistent segments using 24-bit VXLAN Network Identifiers (VNIDs).
26. Which three routing protocols can the Cisco WAN Edge router use for learning reachability information from the service-side interfaces? (Choose three.)
- RIPv1
- EIGRP
- OSPF
- IS-IS
- BGP
Explanation: Topic 25.7.0
The Cisco WAN Edge router functions as the data plane element of the SD-WAN fabric, responsible for establishing secure connectivity and forwarding data between sites. To learn reachability information from the service-side (LAN) interfaces, these routers support several traditional routing protocols:
- OSPF: WAN Edge routers support both OSPFv2 and OSPFv3 for learning routes from the local service-side network.
- EIGRP: This protocol is explicitly used for learning reachability information from service-side interfaces and for brownfield integration with non-SD-WAN sites.
- BGP: This is a standard routing protocol used on the service-side to exchange prefixes with local site routers.
Once these routes are learned from the service-side (configured in VPNs 1 through 65535), they are redistributed into the Overlay Management Protocol (OMP) to be advertised as service-side routes (vRoutes) across the SD-WAN overlay.
Note: While the sources state that RIPv2 is also supported, RIPv1 and IS-IS are not listed as options for learning reachability from the service-side interfaces. (IS-IS is instead recommended for use in the network underlay for physical connectivity).
27. What Cisco Catalyst Center tool detects anomalous behavior and stops its manifestation into security threats?
- Power over Ethernet (PoE)
- AI Endpoint Analytics
- Cisco Secure Network Analytics
- Identity Services Engine (ISE)
Explanation: Topic 23.2.0
Cisco Catalyst Center uses AI Endpoint Analytics and endpoint trust score automation to detect anomalous behavior and prevent its manifestation into security threats. This tool is a core component of the platform's security architecture, providing deep visibility into what endpoints are on the network and allowing for granular macro- and micro-segmentation to limit the attack surface.
As part of the SecOps (Security Operations) capabilities, AI Endpoint Analytics classifies endpoints and helps enforce zero-trust network access. By monitoring endpoint behavior and calculating trust scores, it ensures that only authorized resources are accessed and that potential vulnerabilities are identified through continuous compliance checks. While other tools like Cisco Secure Network Analytics and Identity Services Engine (ISE) are part of the integrated security suite, AI Endpoint Analytics is specifically cited in the sources for its role in stopping the manifestation of anomalous behavior into threats.
28. What Cisco Catalyst Center component combines deep insights with rich context?
- Provisioning
- Design
- Assurance
- Policy
Explanation: Topic 23.3.0
Within the Cisco Catalyst Center architecture, Assurance is the specific component designed to combine deep insights with rich context to deliver a consistent user experience and proactively optimize the network. It acts as a real-time network data collection and analytics engine that uses contextual analysis to validate that business intent has been correctly applied and that desired outcomes are being achieved.
Key functions of the Assurance component include:
- Health Dashboards: Providing at-a-glance visibility into the overall health of network devices, clients, and applications.
- Proactive Issue Resolution: Using AI-driven insights and predictive analytics to identify root causes and suggest remediation steps before they impact the business.
- 360-Degree Views: Offering detailed, drill-down perspectives of specific network elements to facilitate faster troubleshooting.
29. Which statement best describes the Cisco SD-WAN solution?
- The Cisco SD-WAN solution is a software-based, virtual IP fabric overlay network relying on LISP and VXLAN for both wired and wireless LANs.
- The Cisco SD-WAN solution allows service providers to accelerate WAN services directly for enterprise customers.
- The Cisco SD-WAN is a hardware-based solution that covers switching, routing, voice, and VPN for small to medium-sized businesses.
- The Cisco SD-WAN solution is a software-based, virtual IP fabric overlay network that builds a secure, unified connectivity over any transport network (the underlay).
Explanation: Topic 25.2.0
The Cisco Catalyst SD-WAN solution represents a significant shift from older, hardware-based legacy WAN models to a secure, software-based, virtual IP fabric overlay. This overlay architecture is designed to build unified connectivity over any transport network, known as the underlay, which can include the public internet, MPLS, Metro Ethernet, and LTE/4G/5G.
Key characteristics of this solution include:
- Decoupling Planes: It separates the data plane forwarding from the control plane, allowing for centralized intelligence, automation, and simplified management.
- Integration: It fully integrates routing, security, centralized policy, and orchestration into large-scale networks.
- Transport Independence: Because it is software-based and virtualized, it can run over any transport circuits, enabling an active-active mix of different link types to optimize capacity and reduce costs.
- Security: It utilizes a zero-trust security model with strong encryption, end-to-end segmentation, and certificate-based identity for all devices.
In contrast, the option mentioning LISP and VXLAN describes the Cisco SD-Access solution, which is intended for wired and wireless LANs rather than the WAN.
30. Which option describes an industry-standard API that the ONF defines?
- OpenFlex
- REST
- NETCONF
- OpenFlow
Explanation: Topic 26.2.1
OpenFlow is an industry-standard southbound API that is specifically defined by the Open Networking Foundation (ONF). Its primary function is to configure the flow tables in switches, which defines the specific flow path traffic takes through a network.
The other options represent different protocols or architectures:
- NETCONF is a network management protocol standardized by the IETF (Internet Engineering Task Force) used to install, manipulate, and delete device configurations via XML-encoded messages.
- OpFlex (likely the "OpenFlex" mentioned in the query) is an open-standard protocol that utilizes a declarative SDN model, where a controller like the Cisco APIC sends abstract policies to network elements.
- REST (Representational State Transfer) is a web service architecture based on the HTTP request-response model that has not been formally defined by any specific standards body.
31. Which action used by the Cisco Catalyst Center Intent API writes new data at the path that the URL specifies?
Explanation: Topic 26.3.0
The Cisco Catalyst Center Intent API utilizes standard HTTP request-response actions to interact with network resources. According to the sources, the POST action is used specifically to write new data at the path that the URL specifies. Its primary purpose is to create new data on the server.
In contrast, the other listed actions perform different functions:
- GET: Used to retrieve or read data from the specified path.
- PUT: Used to replace or update existing data; it cannot be used to create new data.
- DELETE: Used to remove existing data at the specified path.
32. Which node provides the endpoints to a single anycast Layer 3 gateway?
- control plane node
- border node
- edge node
- intermediate node
Explanation: Topic 24.4.1
In a Cisco SD-Access fabric, the edge node is the component that provides first-hop services for users and devices (endpoints) connected to the fabric. A critical function of the edge node is providing the anycast Layer 3 gateway.
The anycast gateway uses a common IP and MAC address that is present on every edge node sharing a common EID (Endpoint Identifier) subnet. This mechanism ensures that when an endpoint moves from one edge node to another, it does not need to change its default gateway configuration, facilitating seamless host mobility and optimal forwarding. While the control plane node manages the host tracking database and the border node acts as the exit point for the fabric, it is the edge node that directly interfaces with endpoints to provide this unified gateway service.
33. Which three options are characteristics of the Cisco vBond orchestration plane? (Choose three.)
- first point of authentication
- authorizes all control connections
- facilitates fabric discovery
- distributes a list of Cisco vSmart controllers to all Cisco WAN Edge routers
- real-time alerting
- distributes a list of Cisco WAN Edge routers to all Cisco vSmart controllers
Explanation: Topic 25.4.0
The Cisco Catalyst SD-WAN Validator (historically known as vBond) resides on the orchestration plane and is responsible for initial security and connectivity. Its key characteristics include:
- First point of authentication: The Validator is the first point of contact for any device connecting to the SD-WAN overlay. It performs initial authentication for all devices to ensure they are authorized to join the network.
- Authorizing control connections: It uses a zero-trust certificate-based allow list model to authorize all control connections within the fabric.
- Distribution of controller lists: During the deployment process, the Validator automatically distributes a list of available Cisco Catalyst SD-WAN Controllers (vSmart) and the Cisco Catalyst SD-WAN Manager (vManage) to the WAN Edge routers. This enables the routers to establish the necessary control and management plane connections.
Other options provided, such as facilitating fabric discovery, are characteristics of the Control Plane (vSmart), while real-time alerting is a feature of the Management Plane (SD-WAN Manager).