Which two statements regarding Cisco SD-WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two.)
A.
Open Certificate Authority and automated enrollment feature.
B.
By default, all incoming traffic is denied at the transport (WAN) side interfaces.
C.
Only authorized controllers are allowed to communicate back to the vEdge router after the vEdge router establishes connections with the controllers.
D.
In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.
E.
The vEdge routers run on hardened Linux operating systems.
Slide 86 or video Cisco SD-WAN: Reinventing WAN Security-Partner - Video below @3:58 he says: "Building on the principles of zero-trust, vEdge routers provide effective barrier to prevent denial of service attacks against the infrastructure. vEdge routers are locked down appliances that run on a hardened Linux operating system..." and "...As the vEdge router reaches out to controllers and establishes TLS/DTLS connection, it automatically adjusts the kernel level filters to allow this traffic back into the router. Only authorized controllers are allowed to communicate back to the vEdge router..."
https://salesconnect.cisco.com/sc/s/learning-activity-from-plan?ltui__urlRecordId=a1O8c00000BDOt0EAH<ui__urlRedirect=learning-activity-from-plan<ui__parentUrl=learning-plan-detail-standard
C & D:
Only traffic that matches NAT table entries allowed back in. This is predicated on the fact the traffic originated on internal, trusted, vEdge routers.
This section is not available anymore. Please use the main Exam Page.500-490 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
GSouza
7 months, 3 weeks agoTMe392
1 year, 6 months agokejvi
2 years agoMyKasala
2 years, 9 months agoDeviantSpy
3 years, 2 months agoaliG
3 years, 8 months agohelpmmg
3 years, 9 months agosat_be
3 years, 7 months agoMarcorick
3 years, 10 months ago