{"id":23236,"date":"2026-09-26T12:20:58","date_gmt":"2026-09-26T12:20:58","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23236"},"modified":"2026-09-26T12:20:58","modified_gmt":"2026-09-26T12:20:58","slug":"cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-19-q361-380\/","title":{"rendered":"Cisco CCNP Enterprise 300-440 Practice Test Questions and Exam Dumps Part 19 Q361-380"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-440-exam-dumps\"><b>Cisco CCNP Enterprise 300-440 Exam Dumps <\/b><\/a><b>\u00a0and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 361. Which requirement should be evaluated when determining whether dedicated connectivity is appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS record naming conventions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF process identification<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Required bandwidth, performance predictability, and SLA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Router console speed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Required bandwidth, performance predictability, and SLA<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connectivity selection should be based on documented application and business requirements. Bandwidth requirements, performance predictability, availability objectives, and provider SLA commitments are important when comparing shared and dedicated services. A business-critical application may require more predictable service characteristics, but the decision should also consider cost, security, compliance, resiliency, and provider architecture. DNS naming, OSPF process identification, and console settings do not determine the suitability of the connectivity service. Peak utilization and failure scenarios should be included in capacity planning so that the selected service continues to meet application requirements under realistic operating conditions.<\/span><\/p>\n<p><b>Question 362. A company has two cloud connections and wants traffic to prefer one path for outbound communication from the enterprise AS. Which BGP attribute should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MED<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Community<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Local preference<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP local preference is used within an autonomous system to influence outbound path selection. A higher local-preference value is preferred, allowing the enterprise to designate one cloud connection as the preferred exit while retaining another path for redundancy. MED is generally used to influence inbound path selection from a neighboring autonomous system, while origin and community serve different roles in BGP policy. Local preference is therefore appropriate when the requirement is to influence how enterprise routers select an outbound path toward the cloud. The resulting policy should be tested across the relevant routers to ensure consistent path selection.<\/span><\/p>\n<p><b>Question 363. An engineer receives a cloud route through eBGP and another route through OSPF for the same destination. No administrative-distance values have been changed. Which route is normally selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The OSPF route because it is an IGP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Both routes are installed automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The route with the higher metric regardless of protocol<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The eBGP route because its default administrative distance is lower<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The eBGP route because its default administrative distance is lower<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco routers normally assign eBGP an administrative distance of 20 and OSPF an administrative distance of 110. When otherwise comparable routes to the same destination are learned from these protocols, the eBGP route is preferred because it has the lower administrative distance. The routing protocol&#8217;s own metric is considered within that protocol and does not override administrative distance when comparing different protocol sources. Engineers should verify whether administrative-distance values have been customized, because modified values can change the outcome. This distinction is important when integrating cloud BGP connectivity with an internal OSPF environment.<\/span><\/p>\n<p><b>Question 364. A policy-based IPsec connection is established, but traffic from a newly added subnet does not enter the tunnel. Which configuration should be checked first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec traffic selectors or crypto ACLs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF router ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. IPsec traffic selectors or crypto ACLs<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy-based IPsec uses traffic selectors or crypto ACLs to determine which traffic should be protected. If a new enterprise subnet is not included in the protected traffic definition, packets from that subnet may not match the IPsec policy even though the tunnel itself is established. The administrator should verify local and remote protected networks and confirm that the peer has compatible selectors. BGP local preference and OSPF router IDs affect routing rather than IPsec traffic matching, while DNS forwarding affects name resolution. Packet counters and security-association details can provide additional evidence after the selectors are verified.<\/span><\/p>\n<p><b>Question 365. A branch uses a cloud connection shared by voice, video, and bulk data traffic. During congestion, voice quality becomes unacceptable. Which design feature should be implemented or evaluated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP router ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF area numbering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> QoS classification and prioritization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. QoS classification and prioritization<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">QoS classification and prioritization can help protect latency-sensitive traffic during congestion. Voice and interactive video generally have stricter requirements for delay, jitter, and packet loss than bulk data transfers. The network should classify traffic into appropriate queues and apply scheduling or bandwidth policies consistent with the application&#8217;s requirements. DNS caching and routing-protocol identifiers do not control packet treatment during congestion. The engineer should also verify the WAN&#8217;s total capacity, provider QoS capabilities, traffic patterns, and whether the configured policy provides sufficient resources during peak demand.<\/span><\/p>\n<p><b>Question 366. A cloud BGP neighbor is established, but an expected enterprise prefix is not being learned by the cloud. What should the enterprise engineer verify first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP advertised routes toward the cloud neighbor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS resolver configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF hello interval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec encryption algorithm<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. OSPF hello interval<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The most direct verification would actually be the BGP advertised routes toward the cloud neighbor. This shows whether the enterprise is sending the expected prefix and can reveal problems caused by outbound prefix filtering, route maps, redistribution, or route availability. OSPF hello intervals and DNS configuration do not directly verify BGP advertisements. IPsec encryption may be relevant to the transport path, but it does not determine whether a locally known prefix is being advertised by BGP. The engineer should distinguish between a prefix not existing locally, not being advertised, being filtered, or being rejected by the cloud provider.<\/span><\/p>\n<p><b>Question 367. An enterprise wants cloud application traffic to use the Internet connection directly at a branch rather than being sent through a central data center. Which architecture is being considered?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local Internet breakout<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Centralized Internet backhaul<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> East-west segmentation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP route reflection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Local Internet breakout<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local Internet breakout allows selected Internet-bound or SaaS traffic to exit directly from the branch instead of traversing a centralized data center. In an SD-WAN environment, application-aware policies can identify traffic and select the appropriate local Internet path. This can reduce backhaul bandwidth consumption and latency, but security inspection and policy enforcement must also be addressed at the local site. Centralized Internet backhaul uses the opposite traffic model. East-west segmentation concerns internal traffic between workloads or network zones, while BGP route reflection is a control-plane scaling mechanism.<\/span><\/p>\n<p><b>Question 368. A cloud BGP route is received successfully, but the enterprise router continues using another route to the same destination. Which information should be checked to understand the selection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cache contents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP path attributes and route preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec cipher suite only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF authentication password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. BGP path attributes and route preference<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a BGP route is received but another route remains active, the engineer should examine the routing table, administrative distance, next-hop reachability, and BGP path-selection attributes as applicable. If multiple BGP paths exist, attributes such as local preference, AS-path length, origin, MED, and other decision criteria can influence which path is selected. DNS cache, IPsec cipher settings, and OSPF authentication do not directly explain BGP path selection. Troubleshooting should first establish whether the competing route comes from another routing protocol or another BGP path, because the relevant selection process differs.<\/span><\/p>\n<p><b>Question 369. A cloud VPN shows established security associations, but the enterprise application cannot communicate with the cloud subnet. Which troubleshooting approach is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change the DNS TTL<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the OSPF process number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Verify routing, traffic selectors, and IPsec packet counters<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change the BGP router ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Verify routing, traffic selectors, and IPsec packet counters<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An established security association confirms successful negotiation but does not prove that application packets are correctly routed and encrypted. The engineer should verify that the enterprise has a route toward the cloud subnet, that the traffic matches the configured IPsec selectors, and that packet counters increase when test traffic is generated. If counters do not change, the problem may occur before IPsec processing. If counters increase in one direction only, return routing or policy may be involved. DNS TTL, OSPF process numbers, and BGP router IDs do not directly validate the VPN data plane.<\/span><\/p>\n<p><b>Question 370. An enterprise receives cloud prefixes through BGP but wants to accept only a documented set of networks. Which mechanism should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP MSS adjustment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec lifetime<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF cost manipulation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inbound BGP prefix filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Inbound BGP prefix filtering<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Inbound BGP prefix filtering allows the enterprise to control which routes received from the cloud provider are accepted. A prefix list or route policy can explicitly permit approved cloud networks while denying unexpected advertisements. This improves routing control and reduces unintended reachability. TCP MSS affects TCP segment size, IPsec lifetime controls security-association duration, and OSPF cost affects OSPF path selection. These mechanisms do not provide the required BGP route-acceptance control. The filtering policy should be documented and tested whenever the cloud provider adds or changes advertised networks.<\/span><\/p>\n<p><b>Question 371. An organization requires the cloud connectivity service to maintain acceptable performance during peak traffic periods. Which value should be included in capacity planning?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Peak bandwidth demand<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Router hostname length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS suffix count<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF process ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Router hostname length<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The relevant capacity-planning value would actually be peak bandwidth demand. Average utilization alone may not represent the amount of bandwidth required during busy periods. The engineer should estimate peak traffic, application growth, burst behavior, replication, backups, and other services that can increase utilization. Appropriate capacity headroom should also be considered. Router hostname length, DNS suffix count, and OSPF process ID do not determine network capacity. A sound design compares expected peak demand with committed bandwidth and evaluates how QoS, provider SLAs, and redundancy affect application performance.<\/span><\/p>\n<p><b>Question 372. An enterprise routes Internet traffic from a remote site through a central security stack before allowing it to reach the Internet. Which connectivity model is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local Internet breakout<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet backhaul<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> East-west segmentation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct cloud peering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Local Internet breakout<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The described traffic model is Internet backhaul, because the remote site&#8217;s Internet-bound traffic is first transported to a centralized location for security inspection or policy enforcement. Local Internet breakout would send the traffic directly from the remote site to the Internet. Centralized backhaul can simplify security control and logging but may increase latency and consume WAN bandwidth. The design should therefore evaluate central inspection capacity, resiliency, latency, bandwidth, and failure behavior. East-west segmentation concerns internal workload communication, while direct cloud peering does not describe centralized Internet egress.<\/span><\/p>\n<p><b>Question 373. A cloud application is reachable in one direction, but the return traffic is dropped by a stateful firewall. What should the engineer investigate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cache duration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF process ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asymmetric routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP origin code only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. BGP origin code only<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The most relevant issue would actually be asymmetric routing. If forward and return traffic traverse different paths, a stateful firewall may not see both directions of a session and can drop packets that do not match its expected state. The engineer should trace both directions of the flow and examine routing decisions, firewall state, and return-path reachability. DNS cache duration does not normally determine packet-path symmetry. OSPF and BGP attributes may influence routing, but the operational symptom described specifically requires investigation of asymmetric forwarding and its interaction with stateful security devices.<\/span><\/p>\n<p><b>Question 374. An enterprise wants to verify whether a cloud provider is sending a specific route to its BGP neighbor. Which information is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP received routes from the cloud neighbor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec transform settings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF interface descriptions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. IPsec transform settings<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The most direct information would actually be the BGP received routes from the cloud neighbor. This allows the engineer to determine whether the expected prefix has been received and then investigate filtering or route-selection issues if it is not installed. IPsec transform settings describe encryption parameters and do not show which BGP prefixes have been received. DNS records and OSPF interface descriptions are also unrelated to BGP route reception. The troubleshooting process should distinguish between the cloud not advertising the route, the enterprise not receiving it, inbound filtering, and route-selection problems.<\/span><\/p>\n<p><b>Question 375. A cloud connectivity architecture uses two physically separate circuits, but both terminate on the same enterprise edge router. Which failure remains a concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS TTL expiration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failure of the shared edge router<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP cannot use two sessions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec cannot use redundant paths<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Failure of the shared edge router<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Two physical circuits terminating on the same edge router provide link redundancy but leave the router itself as a common failure point. If that router fails, both circuits may become unavailable even though the circuits are physically separate. Greater resiliency can be achieved by distributing connections across redundant edge devices and, where appropriate, separate facilities or providers. BGP can operate across multiple sessions, and IPsec can be designed with redundant connectivity. DNS TTL does not eliminate an edge-router single point of failure. The complete failure domain should be considered when assessing resiliency.<\/span><\/p>\n<p><b>Question 376. A cloud BGP session is established, but the enterprise does not receive any expected cloud prefixes. Which sequence is most appropriate for troubleshooting?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change DNS records, then modify OSPF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Verify BGP session state, received routes, and inbound policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace the IPsec cipher immediately<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase TCP MSS without testing routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Change DNS records, then modify OSPF<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The appropriate troubleshooting sequence would actually be to verify BGP session state, received routes, and inbound policy. A session being established does not guarantee that routes are being advertised, received, or accepted. The engineer should verify the cloud neighbor&#8217;s state, inspect received-route information, and check inbound prefix filters or routing policies. DNS records and TCP MSS do not directly explain missing BGP prefixes. Changing encryption parameters without evidence can introduce additional variables. A structured approach should isolate route advertisement, reception, filtering, and installation as separate troubleshooting stages.<\/span><\/p>\n<p><b>Question 377. An SD-WAN application policy requires a cloud path to meet a maximum latency and packet-loss threshold. What should happen when the preferred path no longer meets those requirements and an alternate path is available?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the measurements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all BGP sessions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use the policy to select a path that meets the defined requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove all application policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use the policy to select a path that meets the defined requirements<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application-aware SD-WAN policy can evaluate measured network characteristics against configured performance thresholds. If the preferred path no longer satisfies the requirements and an alternate path meets them, policy can steer the application toward the qualifying path according to the configured design. This is different from simply selecting a static route without considering application performance. The thresholds should be based on documented application requirements, and the design should specify what happens when no available path satisfies the required values. Monitoring should confirm that actual path changes match the intended policy behavior.<\/span><\/p>\n<p><b>Question 378. An enterprise uses BGP over redundant cloud connections. During a provider outage, traffic fails over successfully but takes longer than the application&#8217;s requirement. Which area should be optimized?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS record naming<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Router hostname<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF area naming<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failure detection and routing convergence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Failure detection and routing convergence<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If failover works but takes longer than the application&#8217;s requirement, the engineer should investigate failure-detection mechanisms and routing convergence. Relevant factors may include BGP timers, interface or tunnel tracking, path-monitoring mechanisms, route-withdrawal behavior, and the time required to install the alternate route. The design should balance faster convergence with stability so that transient events do not cause unnecessary route flapping. DNS naming, router hostnames, and OSPF area naming do not directly address BGP failover time. Measurements from controlled tests should be compared with the application&#8217;s documented recovery requirement.<\/span><\/p>\n<p><b>Question 379. A cloud application requires communication between two private application segments, and the security team requires inspection between them. Which traffic type should be analyzed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> North-south Internet traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> East-west traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NTP traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. North-south Internet traffic<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The described communication is actually east-west traffic because it occurs between two internal application segments. East-west flows are important in cloud security designs because internal workloads may have different trust levels and security requirements. The security architecture should define which segment-to-segment flows are permitted and where inspection or segmentation controls are enforced. North-south traffic generally describes traffic entering or leaving an environment, including Internet-bound flows. DNS and NTP are protocols and do not describe the traffic direction. Proper east-west policy should also consider inspection capacity and failure behavior.<\/span><\/p>\n<p><b>Question 380. An enterprise validates a redundant cloud connection by disconnecting the primary circuit. The backup path becomes active, but the application remains unavailable. Which additional area should be checked?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Router hostname<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> End-to-end routing and application return path<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS suffix capitalization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP community description<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. End-to-end routing and application return path<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Successful network-path failover does not necessarily guarantee application reachability. After the backup path becomes active, the engineer should verify end-to-end routing in both directions, including the cloud-side return route toward the enterprise application subnet. Security policies, NAT behavior, IPsec selectors, and application dependencies may also need validation. Router hostnames, DNS suffix capitalization, and BGP community descriptions do not directly establish end-to-end reachability. A proper failover test should therefore validate not only route convergence but also actual application connectivity and the complete forward and return traffic paths.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Enterprise 300-440 Exam Dumps \u00a0and Practice Test Dumps &nbsp; Question 361. Which requirement should be evaluated when determining whether dedicated connectivity is appropriate? DNS record naming conventions OSPF process identification Required bandwidth, performance predictability, and SLA Router console speed Correct Answer: 3. Required bandwidth, performance predictability, and SLA Explanation :- Connectivity [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23236"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23236"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23236\/revisions"}],"predecessor-version":[{"id":23237,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23236\/revisions\/23237"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}