Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 500-490 Exam - Topic 3 Question 73 Discussion

Which two statements regarding Cisco SD-WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two.)
C) In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.
A) The vEdge routers run on hardened Linux operating systems.
B) Only authorized controllers are allowed to communicate back to the vEdg e router after the vEdge router establishes connection with the controllers.
D) Open Certificate Authority and automated enrollment feature.
E) By default, all incoming traffic is denied at the transport (WAN) side interfaces.

Cisco 500-490 Exam - Topic 3 Question 73 Discussion

Actual exam question for Cisco's 500-490 exam
Question #: 73
Topic #: 3
[All 500-490 Questions]

Which two statements regarding Cisco SD-WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Merlyn
9 months ago
I agree with A and B, they really help secure the network.
upvoted 0 times
...
Justine
9 months ago
C is also a good option, but I’m not sure about D.
upvoted 0 times
...
Nicholle
10 months ago
Wait, does E mean all traffic is blocked by default? That's surprising!
upvoted 0 times
...
Lou
10 months ago
I think B is more important than A.
upvoted 0 times
...
Lou
10 months ago
A and E are definitely the right choices.
upvoted 0 times
...
Elenora
10 months ago
I recall that denying incoming traffic by default is a common security practice, so option E might be a good choice too.
upvoted 0 times
...
Mirta
11 months ago
I feel like I studied about hardened operating systems, but I'm not convinced that option A is directly related to mitigating DoS attacks.
upvoted 0 times
...
Lisandra
11 months ago
I'm not entirely sure about the specifics, but I remember something about traffic being restricted based on state tables. Maybe that's option C?
upvoted 0 times
...
Crissy
11 months ago
I think option B sounds familiar because it emphasizes authorized communication, which is crucial for security.
upvoted 0 times
...
Jesus
11 months ago
I remember learning about the default deny policy on the WAN interfaces in option E. That seems like a good security measure to mitigate DoS attacks by blocking unauthorized traffic. I'll make sure to select that one as well.
upvoted 0 times
...
Leatha
11 months ago
The open certificate authority and automated enrollment feature in option D could also be relevant, as it helps with secure authentication. But I'm not as confident about that one. I'll focus on options B and C for now.
upvoted 0 times
...
Vilma
11 months ago
Okay, I think the key here is controlling the communication back to the vEdge routers. Options B and C both seem relevant, as they restrict access and only allow authorized traffic. I'll mark those two.
upvoted 0 times
...
Virgina
11 months ago
Hmm, I'm a bit unsure about this one. I know the vEdge routers run on a hardened Linux OS, but I'm not sure if that's enough on its own to mitigate DoS attacks. I'll need to review the other options more closely.
upvoted 0 times
...
Candida
11 months ago
This looks like a tricky question about Cisco SD-WAN security features. I'll need to carefully read through the options and think about which ones would help mitigate DoS attacks.
upvoted 0 times
...
Serina
1 year ago
Ooh, this is a tricky one. I'm going to go with B and E. Gotta love that hardened Linux and default deny-all approach to keep those DoS attackers at bay!
upvoted 0 times
Chara
1 year ago
User3: Definitely, those features help keep the infrastructure secure from potential attacks.
upvoted 0 times
...
Cristen
1 year ago
User2: Agreed, having only authorized controllers communicate and denying all incoming traffic by default is key.
upvoted 0 times
...
Jamie
1 year ago
User1: I think B and E are the way to go for mitigating DoS attacks.
upvoted 0 times
...
...
Sanjuana
1 year ago
I'm going with B and C. Controlling the communication back to the vEdge routers and restricting the incoming traffic are key for protecting the infrastructure.
upvoted 0 times
Diego
1 year ago
Yes, restricting the incoming traffic based on state table entries is also important for security.
upvoted 0 times
...
Kristeen
1 year ago
I agree, controlling the communication back to the vEdge routers is crucial.
upvoted 0 times
...
...
Kattie
1 year ago
Haha, I bet the right answers involve some kind of security lockdown. These vEdge routers must be like digital fortresses against those pesky DoS attacks!
upvoted 0 times
...
Latrice
1 year ago
B and E seem to be the way to go. Limiting the allowed communication and denying all incoming traffic by default is a solid security approach.
upvoted 0 times
...
Estrella
1 year ago
I'm not sure about A, but I think E is definitely one of the correct answers. Denying incoming traffic is crucial for security.
upvoted 0 times
...
Amber
1 year ago
I agree with Audra. A and E make sense because hardened Linux OS and denying incoming traffic can help mitigate DoS attacks.
upvoted 0 times
...
Audra
1 year ago
I think the answer is A and E.
upvoted 0 times
...
Berry
1 year ago
I think B and C are the correct answers. The vEdge routers need to be hardened against unauthorized access, and controlling the traffic flow is crucial for mitigating DoS attacks.
upvoted 0 times
Lashandra
1 year ago
By default, all incoming traffic is denied at the transport interfaces to prevent unauthorized access.
upvoted 0 times
...
Dawne
1 year ago
Controlling the traffic flow based on state table entries is crucial for security.
upvoted 0 times
...
Hyun
1 year ago
It's important to only allow authorized controllers to communicate with the vEdge router.
upvoted 0 times
...
Nobuko
1 year ago
I agree, B and C are the correct answers.
upvoted 0 times
...
...

Save Cancel