300-440 Sample Questions & Answers
IPsec and SD-WAN connectivity into the cloud tie for the largest share, alongside internet, private and SaaS connectivity models, resiliency and compliance-driven design, and diagnosing routing or connectivity problems.
Launch the full 300-440 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
IPsec Cloud Connectivity · Configure routing on Cisco IOS XE to integrate with cloud networks using BGP
A network administrator is configuring a route-based IPsec VPN from a Cisco IOS XE router to a Google Cloud VPN endpoint. BGP will be used to exchange routes. Which configuration snippet is essential for enabling BGP to run over the tunnel interface?
Show answer & explanation
Correct answer: B
This configuration correctly sets up a Virtual Tunnel Interface (VTI). A VTI creates a routable interface, which is essential for running dynamic routing protocols like BGP over the IPsec tunnel. The
tunnel mode ipsec ipv4andtunnel protection ipsec profile MYPROFILEcommands bind the IPsec policy to the tunnel interface. The crypto map configuration is used for policy-based VPNs, which do not support dynamic routing protocols effectively. - Question 2Beginner
Operation · Diagnose Cisco SD-WAN internet-based secure cloud connectivity
A company has deployed a Cisco SD-WAN fabric and is using vManage to monitor connectivity. An administrator notices that a vEdge router at a branch site has lost connectivity to one of its two available transports (MPLS). In the vManage dashboard, what visual indicator represents this loss of connectivity for the specific transport?
Show answer & explanation
Correct answer: B
In Cisco SD-WAN, each transport on a vEdge is represented by a TLOC (Transport Locator). When a transport goes down, the vEdge loses its BFD sessions over that path, and the OMP route associated with that TLOC is withdrawn. In the vManage dashboard, specifically under the device's control connections monitoring, the entry for the TLOC associated with the failed MPLS transport will disappear or show as down. The vEdge icon itself will likely remain green as long as it has connectivity through its other transport.
- Question 3Advanced
Design · Recommend a connectivity model to meet regulatory compliance
An architect is designing a network for a government agency that requires connectivity to AWS GovCloud. The solution must adhere to FEDRAMP High standards. Which connectivity model and security feature are most appropriate to meet these strict compliance requirements?
Show answer & explanation
Correct answer: D
FEDRAMP High requires stringent security controls. AWS Direct Connect provides a private, dedicated connection that bypasses the public internet. Adding MACsec provides point-to-point security at Layer 2, encrypting all data between the on-premises router and the AWS Direct Connect device. This combination of a private circuit and strong, line-rate encryption is the most suitable approach for meeting the high-security posture demanded by FEDRAMP High compliance.
- Question 4Advanced
Design · Recommend the connectivity model based on network architecture requirements
A retail company is migrating its e-commerce platform to a multi-cloud architecture using both AWS and Azure. The on-premises data center hosts the primary inventory database. The company requires a connectivity solution that provides high availability, consistent low latency for database synchronization, and the ability to dynamically route traffic between the on-premises environment and both clouds.
The current on-premises network is built on Cisco routers. The IT team is small, so a solution that simplifies routing management is preferred. The average bandwidth requirement is 2 Gbps, with peaks up to 5 Gbps during sales events. The CIO has mandated that a single provider failure should not cause a complete outage of cloud connectivity. What is the most suitable design recommendation?
Show answer & explanation
Correct answer: D
This is the optimal solution. It meets all requirements: high availability (redundant connections to SDCI), consistent low latency (private backbone), sufficient bandwidth (10 Gbps circuits), and simplified management. The SDCI provider abstracts the complexity of connecting to multiple clouds, allowing the IT team to manage connectivity and routing through a single portal. It also provides a clear path for routing between AWS and Azure over the private SDCI backbone, fulfilling the dynamic routing requirement efficiently.
- Question 5Beginner
SD-WAN Cloud Connectivity · Configure Cisco SD-WAN internet-based secure cloud connectivity
What is the primary function of a Cisco SD-WAN vBond Orchestrator in the control plane?
Show answer & explanation
Correct answer: C
The vBond Orchestrator is the initial point of contact for any device joining the SD-WAN fabric. Its primary roles are to authenticate the vEdge router (ensuring it's on a whitelist), authorize it to join the fabric, and provide the IP addresses of the vManage and vSmart controllers. It effectively bootstraps the device into the control plane. Policy distribution is handled by vSmart, and the GUI is provided by vManage.
- Question 6IntermediateSelect 2
IPsec Cloud Connectivity · Configure routing on Cisco IOS XE to integrate with cloud networks using BGP
A network engineer is configuring a Cisco IOS XE router to connect to an AWS Virtual Private Gateway (VGW) via IPsec. The engineer must ensure that if the primary tunnel fails, traffic automatically reroutes to a secondary tunnel. BGP is used for routing. Which two configuration elements are essential for enabling this automatic failover? (Select TWO)
Show answer & explanation
Correct answers: B, C
BGP uses attributes like local preference to determine the best path. By setting a higher local preference on routes received from the primary tunnel's BGP neighbor, the router will prefer that path. When the primary tunnel fails, its BGP session goes down, those routes are withdrawn, and BGP automatically selects the routes from the secondary tunnel.
AWS provides two tunnel endpoints for redundancy. To connect to both, two distinct VTIs must be configured on the IOS XE router. Each VTI will have its own source/destination and establish a separate BGP peering session, forming the foundation for the redundant setup.
- Question 7Intermediate
Architecture Models · Describe private connectivity to cloud providers
When comparing private connectivity models for a hybrid cloud environment, what is a primary advantage of using a colocation provider over a direct MPLS provider circuit?
Show answer & explanation
Correct answer: B
A key advantage of a colocation facility is its carrier-neutral ecosystem. These facilities typically host on-ramps for multiple cloud providers (AWS, Azure, GCP, etc.). An enterprise can establish a presence in the colo and then use simple, low-cost cross-connects to reach multiple clouds. An MPLS circuit is typically a point-to-point service to a single destination, making multi-cloud integration more complex and less flexible.
- Question 8Intermediate
Operation · Diagnose routing issues on Cisco IOS XE to integrate with cloud networks using BGP
A network administrator is diagnosing a BGP peering issue over an Azure ExpressRoute circuit. The on-premises Cisco router is not receiving any prefixes from the Azure VNet. The administrator confirms physical connectivity and that the BGP neighbor state is
Established. What is the most likely cause of this issue within the Azure environment?Show answer & explanation
Correct answer: C
Even when a BGP session is established over ExpressRoute, Azure does not automatically advertise the VNet's address space. The administrator must explicitly associate a route filter or advertise the VNet's prefixes to the circuit. A common oversight is to have a working BGP session but no prefixes being advertised from the Azure side, resulting in one-way or no connectivity. If the BGP state is
Established, the gateway is provisioned correctly. - Question 9Beginner
SD-WAN Cloud Connectivity · Configure Cisco SD-WAN policies (north/south and east/west)
True or False: In a Cisco SD-WAN solution, a centralized data policy configured on vSmart is pushed down and enforced directly on the vEdge routers' data planes.
Show answer & explanation
Correct answer: A
This statement is true. While data policies are configured centrally on vSmart for ease of management, vSmart compiles and distributes these policies to the vEdge routers via OMP. The vEdge routers then install these policies into their local data plane forwarding hardware or software, where the actual traffic classification, matching, and action (e.g., permit, drop, redirect) are performed on packets as they are processed.
- Question 10Intermediate
SD-WAN Cloud Connectivity · Configure Cisco SD-WAN policies (north/south and east/west)
A manufacturing company is deploying a Cisco SD-WAN solution to connect its factories and corporate headquarters. The primary goal is to secure the network by segmenting traffic. The company has defined three main traffic profiles: Corporate users, IoT devices on the factory floor, and Guest Wi-Fi.
The security policy dictates that IoT devices can only communicate with specific servers in the data center and are not allowed to access the internet or the corporate user segment. Corporate users need access to both data center resources and the internet. Guest Wi-Fi traffic must be isolated and sent directly to the internet at the local site.
Which SD-WAN feature should be the primary component used to implement this network segmentation and enforce the security policies?
Show answer & explanation
Correct answer: C
The core feature for network segmentation in Cisco SD-WAN is the use of service-side VPNs, which are analogous to VRFs. By assigning each traffic profile (Corporate, IoT, Guest) to a different VPN, the administrator creates separate, isolated routing tables. This provides the foundational segmentation. Centralized data policies can then be used to control traffic flow between these VPNs (e.g., allowing Corporate to talk to the data center VPN) and to direct traffic within a VPN (e.g., sending Guest VPN traffic to a local internet exit).
Ready for the real thing?
The full 300-440 simulator has every exam-style question, timed mode, and instant scoring.