QuestionQ14

Defend

Which two statements about Cisco SD-WAN vEdge routers help mitigate DoS attacks against the infrastructure?

Choose two
  • A Open Certificate Authority and automated enrollment feature.
  • B By default, all incoming traffic is denied at the transport (WAN) side interfaces.
  • C Only authorized controllers are allowed to communicate back to the vEdge router after the vEdge router establishes connections with the controllers.
  • D In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.
  • E The vEdge routers run on hardened Linux operating systems.
Explanation

Cisco SD-WAN authenticates and authorizes fabric devices before they establish secure control channels, preventing unauthorized controllers from communicating as trusted control-plane peers. With Direct Internet Access using NAT, return traffic is allowed through the NAT entry created for an initiated connection, limiting unsolicited inbound traffic.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!