DevNet Associate (DEVASC) v1.0Cisco Platforms and DevelopmentHard
A global organization is deploying Cisco SD-WAN across its branches and needs to ensure consistent security policies are applied everywhere. The security team wants to define these policies centrally and programmatically push them to all vEdge routers. Which type of policy in Cisco SD-WAN vManage is used to implement security rules for traffic traversing the overlay network, including firewall, IPS, and URL filtering?
- AControl Policy
- BData Policy
- CApplication-Aware Routing Policy
- DSecurity Policy
Show answer & explanationAnswer & explanation
Correct answer: D. Security Policy
In Cisco SD-WAN vManage, Security Policies are specifically designed to define and apply security rules such as firewall, IPS, and URL filtering for traffic within the overlay network, ensuring consistent enforcement across vEdge routers.
Why the other options are wrong
- A. Control Policies influence routing decisions and topology, not security features like firewall or IPS.
- B. Data Policies manipulate data plane traffic characteristics like QoS and traffic engineering, but do not directly define security services like firewall or IPS.
- C. Application-Aware Routing Policies select the best path for applications based on performance, not security services.
Cisco SD-WAN Security Policy
Cisco SD-WAN Security Policies, configured in vManage, define a comprehensive set of security services (e.g., firewall, IPS, URL filtering, advanced malware protection) to protect traffic traversing the SD-WAN overlay network.
- Applied to vEdge routers.
- Enforces consistent security posture across the WAN.
- Configured and managed centrally from vManage.
Memory trick: vManage policies steer traffic and secure the path.