exam questions

Exam 400-007 All Questions

View all questions & answers for the 400-007 exam

Exam 400-007 topic 1 question 11 discussion

Actual exam question from Cisco's 400-007
Question #: 11
Topic #: 1
[All 400-007 Questions]

SDWAN networks capitalize the usage of broadband Internet links over traditional MPLS links to offer more cost benefits to enterprise customers. However, due to the insecure nature of the public Internet, it is mandatory to use encryption of traffic between any two SDWAN edge devices installed behind NAT gateways.
Which overlay method can provide optimal transport over unreliable underlay networks that are behind NAT gateways?

  • A. DTLS
  • B. TLS
  • C. IPsec
  • D. GRE
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
The1BelowAll
1 month ago
Selected Answer: C
In my experience in Cisco SD-WAN, IPsec is used for edge to edge. DTLS or TLS is for Edge to controller.
upvoted 2 times
...
Redrum702
6 months, 1 week ago
Answer is A
upvoted 1 times
...
Seawanderer
7 months, 3 weeks ago
Selected Answer: A
• DTLS is designed to provide security for datagram-based applications by allowing them to communicate in a way that prevents eavesdropping, tampering, and message forgery. It is based on TLS, but adapted for use over UDP, which makes it suitable for unreliable networks. • DTLS supports NAT traversal and can handle the packet loss, reordering, and fragmentation typical of UDP-based communication over public Internet links. • This makes DTLS an excellent choice for securing SD-WAN traffic over broadband Internet links, especially when NAT gateways are involved.
upvoted 3 times
...
XalaGyan
1 year ago
Selected Answer: A
Guys please help me understand this question. Keywords are encryption + overlay protocol + SDWAN (no specific Cisco/Viptella hints) + unreliable underlay + nat. unreliable underlay = UDP in my head = Datagram NAT= TLS derivatives or IPSEC NAT-T Overlay , possible options are DTLS and IPSEC For IPSEC i remember to have used encryption accelerator cards, meaning heavy cpu needed TLS i have never had any specific requirements and it worked, hence i assume that it is easier on the cpu and opt for TLS. Final thought taking all above together is DTLS which is a supported Overlay, supports unreliable networks by the virtue of UDP and provides encryption. My answer will be A / DTLS please share your thoughts where i got wrong along the path. thank you
upvoted 2 times
...
Rim007
1 year, 3 months ago
Selected Answer: C
IPSEC is the answer in my opinion, because viptella use IPSEC between vEdges.
upvoted 2 times
...
namashivaya
1 year, 5 months ago
Selected Answer: C
Edge to Edge communication IPSEC be it behind nat or without NAT https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-design-guide.html#Components
upvoted 4 times
...
Horvoe
1 year, 7 months ago
Selected Answer: C
This actually makes sense https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/security-overview.html
upvoted 2 times
...
bdp123
1 year, 7 months ago
Selected Answer: C
I believe they are referring to protocol between any two edge devices - DTLS or TLS is used between edge device and SMART or vBOND devices and IPSEC is used between edge devices. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/security-overview.html
upvoted 3 times
...
cryptotafkar
1 year, 9 months ago
Selected Answer: A
One of the primary challenges with IPsec is its compatibility with NAT (Network Address Translation). IPsec was designed before NAT became prevalent, and as a result, it can experience difficulties traversing NAT devices. Although there are extensions like NAT-T (NAT Traversal) that help IPsec to work better with NAT, the process can still be more complex and less reliable than DTLS, which was designed with NAT traversal in mind.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago