Pass4itsure > Cisco > CCNP Enterprise > 300-440 > 300-440 Online Practice Questions and Answers

300-440 Online Practice Questions and Answers

Questions 4

Refer to the exhibits.

An engineer needs to configure a site-to-site IPsec VPN connection between an on premises Cisco IOS XE router and Amazon Web Services (AWS). Which two IP prefixes should be used to configure the AWS routing options? (Choose two.)

A. 30.30.30.0/30

B. 20.20.20.0/24

C. 30.30.30.0/24

D. 50.50.50.0/30

E. 40.40.40.0/24

Buy Now
Questions 5

A cloud engineer is setting up a new set of nodes in the AWS EKS cluster to manage database integration with Mongo Atlas. The engineer set up security to Mongo but now wants to ensure that the nodes are also secure on the network side. Which feature in AWS should the engineer use?

A. EC2 Trust Lock

B. security groups

C. tagging

D. key pairs

Buy Now
Questions 6

Refer to the exhibit.

An engineer needs to configure a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router and Amazon Web Services (AWS). Which configuration command must be placed in the blank in the code to complete the tunnel configuration?

A. address 20.20.20.21

B. address 192.10.10.10

C. tunnel source 20.20.20.21

D. tunnel source 192.10.10.10

Buy Now
Questions 7

Refer to the exhibit.

An engineer successfully brings up the site-to-site VPN tunnel between the remote office and the AWS virtual private gateway, and the site-to-site routing works correctly. However, the end-to-end ping between the office user PC and the AWS EC2 instance is not working.

Which two actions diagnose the loss of connectivity? (Choose two.)

A. Check the network security group rules on the host VNET.

B. Check the security group rules for the host VPC.

C. Check the IPsec SA counters.

D. On the Cisco VPN router, configure the IPsec SA to allow ping packets.

E. On the AWS private virtual gateway, configure the IPsec SA to allow ping packets.

Buy Now
Questions 8

Which feature is unique to Cisco SD-WAN IPsec tunnels compared to native IPsec VPN tunnels?

A. real-time dynamic path selection

B. tunneling protocols

C. end-to-end encryption

D. authentication mechanisms

Buy Now
Questions 9

A company has multiple branch offices across different geographic locations and a centralized data center. The company plans to migrate Its critical business applications to the public cloud infrastructure that is hosted in Microsoft Azure. The company requires high availability, redundancy, and low latency for its business applications. Which connectivity model meets these requirements?

A. ExpressRoute with private peering using SDCI

B. hybrid connectivity with SD-WAN

C. AWS Direct Connect with dedicated connections

D. site-to-site VPN with Azure VPN gateway

Buy Now
Questions 10

Refer to the exhibits.

An engineer must redistribute OSPF internal routes into BGP to connect an on-premises network to a cloud provider without introducing extra routes. Which two commands must be configured on router R2? (Choose two.)

A. router ospf 1

B. router bgp 100

C. redistribute ospf 1

D. redistribute bgp 100

E. redistribute ospf 1 match internal external

Buy Now
Questions 11

Refer to the exhibit.

While troubleshooting an IPsec connection between a Cisco WAN edge router and an Amazon Web Services (AWS) endpoint, a network engineer observes that the security association status is active, but no traffic flows between the devices What is the problem?

A. wrong ISAKMP policy

B. identity mismatch

C. wrong encryption

D. IKE version mismatch

Buy Now
Questions 12

DRAG DROP

An engineer must configure an AppGoE service node for WAN optimization for applications that are hosted in the cloud using Cisco vManage for C8000V or C8500L-8S4X devices. Drag and drop the steps from the left onto the order on the right to complete the configuration.

Select and Place:

Buy Now
Questions 13

DRAG DROP

An engineer must edit the settings of a site-to-site IPsec VPN connection between an on- premises Cisco IOS XE router and Amazon Web Services (AWS). IPsec must be configured to support multiple peers and failover after 120 seconds of idle time on the first entry of the crypto map named Cisco. Drag and drop the commands from the left onto the order on the right.

Select and Place:

Buy Now
Exam Code: 300-440
Exam Name: Designing and Implementing Cloud Connectivity (ENCC)
Last Update: Nov 25, 2024
Questions: 38
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99