시험덤프
매달, 우리는 1000명 이상의 사람들이 시험 준비를 잘하고 시험을 잘 통과할 수 있도록 도와줍니다.
  / VNX301 덤프  / VNX301 문제 연습

Versa Networks VNX301 시험

Versa Certified Administrator - SD-WAN Specialist 온라인 연습

최종 업데이트 시간: 2026년06월04일

당신은 온라인 연습 문제를 통해 Versa Networks VNX301 시험지식에 대해 자신이 어떻게 알고 있는지 파악한 후 시험 참가 신청 여부를 결정할 수 있다.

시험을 100% 합격하고 시험 준비 시간을 35% 절약하기를 바라며 VNX301 덤프 (최신 실제 시험 문제)를 사용 선택하여 현재 최신 47개의 시험 문제와 답을 포함하십시오.

 / 2

Question No : 1


You want to ensure that devices in your branch sites cannot source traffic from IP addresses that are not assigned to the branch sites.
What will solve this problem?

정답:
Explanation:
The correct answer is B. The requirement is to stop branch devices from sourcing traffic using IP addresses that do not belong to the branch. This is a source-address enforcement problem, so the correct control is a stateful firewall policy that permits only traffic whose source IP address matches the valid branch LAN prefix or branch-assigned address range. Versa’s stateful firewall configuration documentation explains that firewall policy rules include source matching, where the administrator selects the source zone and one or more source addresses to which the rule applies.
By creating an allow rule for the legitimate branch source prefixes and placing a deny rule for all other sources from the branch LAN zone, the VOS device prevents spoofed or unauthorized source addresses from leaving the branch. This is consistent with Versa security policy behavior, where firewall rules evaluate traffic based on zones, addresses, services, applications, and other match criteria. Captive portal verifies user identity but does not directly prevent IP spoofing. An IP filter profile based on applications does not ensure the source address belongs to the branch.
Option D is incorrect because allowing traffic to the assigned LAN range controls destination traffic, while this requirement is about validating the source IP address of outbound branch traffic.

Question No : 2


Which three notification methods does Versa Director allow you to configure for sending system event notifications? (Choose three.)

정답:
Explanation:
The correct answers are A, B, and E. Versa Director supports multiple notification and event-publishing mechanisms. For email-style system and alarm notifications, Versa Director supports SMTP configuration. The Director documentation lists Configure SMTP Notifications and explains that email templates require SMTP notifications to send test emails or operational messages.
Versa Director also supports webhook notifications. The Director GUI overview states that Notification Configuration includes webhook-based notifications for alarms, and the Director documentation includes a dedicated workflow for configuring webhook notifications for alarms.
Kafka is also a supported event-notification method. Versa’s Kafka Notifications documentation states that Versa Director can publish event notifications to an Apache Kafka server when events occur on a Director node or a VOS device. It also lists notification topics for device events, Director events, Director task notifications, and object-change event notifications.
MMS is not a Versa Director system event notification method. SMS can be configured for text messaging in some notification contexts, but for the three methods listed for system event notifications in this answer set, the verified options are SMTP, Webhook, and Kafka.

Question No : 3


You have deployed a group of devices in Versa Director, and the field technicians have performed the onboarding tasks onsite. One of the devices has not finished the onboarding process and does not appear in the Appliances list in Versa Director. The onboarding VPN tunnel from the device to the Controller is up.
Which two actions would help you solve this problem? (Choose two.)

정답:
Explanation:
The correct answers are A and C. If the onboarding VPN tunnel from the branch device to the Controller is up, the branch has reached at least the initial staging/control connectivity stage. Versa troubleshooting documentation explains that after a branch establishes IPsec connectivity to the Controller, the Controller sends a branch-connect notification to Versa Director. In response, Director pushes staging configuration and continues the onboarding lifecycle. If the expected later notification is not seen, the branch has not completed staging and further onboarding/debug steps are required.
The Tasks list in Versa Director is useful because device deployment and onboarding actions are executed as Director tasks. If template commit, workflow deployment, device claiming, or configuration push fails, the task output can show the error. The Unknown Devices dashboard is also relevant because a device that reaches the Controller but cannot be matched or fully associated with an expected workflow/appliance record may appear as an unknown device awaiting administrative review. The Monitor dashboard is not the best choice because the device is missing from the Appliances list and has not completed onboarding. Resource Pool is related to connector resources, not branch onboarding completion.

Question No : 4


Examine the exhibit below.



You are configuring Class of Service on a WAN-facing network interface, and you want to perform DSCP rewrite on the packets that are forwarded to the WAN. However, you are not able to turn on DSCP rewrite.
Referring to the exhibit, what is the cause of this issue?

정답:
Explanation:
In the exhibit, the Add Associate Interface/Network window has Interface selected, and the interface name is set to vni-0/0. The DSCP rewrite option is not available because rewrite behavior is intended to be applied at the network association level for the WAN network, not directly while associating only the physical/logical interface. For WAN-facing CoS, the scheduler and shaping parameters can be attached to an interface, but DSCP rewrite policies are applied to remark traffic as it exits through a network context.
Versa SD-WAN design documentation explains that QoS rewrite rules rewrite packet QoS attributes as packets leave the VOS device, and that rewrite rules can modify IEEE 802.1p bits, IPv4 TOS/DSCP bits, and IPv6 traffic class bits. It also explains that a rewrite policy is commonly applied on a WAN network to remark traffic based on the forwarding class and loss priority assigned by QoS or App QoS policies. In the design example, Versa explicitly describes applying a QoS propagation or rewrite policy on the MPLS WAN network to remark traffic to a DSCP value. Therefore, the issue is the association type: it is set to Interface, not Network.

Question No : 5


Examine the exhibit below.



A DoS Profile shown in the exhibit is applied to an SD-WAN branch.
Referring to the exhibit, which statement is correct?

정답:
Explanation:
The correct answer is B. The DoS profile in the exhibit is a Classified Profile using Source IP Only as the classification key. For TCP flood protection, the profile is enabled and shows an Alarm Rate of 5000 packets per second, an Activate Rate of 7000 packets per second, a Maximum Rate of 100000 packets per second, a Drop Period of 300 seconds, and an action of Random. This means the first threshold, 5000 pps, is used to trigger alarm behavior, while the second threshold, 7000 pps, activates the configured mitigation action. Since the selected action is Random, packets are randomly dropped when the TCP rate reaches the activate threshold.
Versa documentation shows that DoS policies can match traffic using source, destination, service, application, schedule, IP version, DSCP, and other conditions, and that a DoS policy can set either an aggregate or classified DoS profile. It also documents that DoS policies support enforcement actions and logging through LEF profiles for DoS events. Therefore, 7000 pps does not merely generate an alarm, and it does not mean complete dropping. Complete dropping is not selected in the exhibit.

Question No : 6


Which two methods would be used to upgrade deployed VOS branch devices? (Choose two.)

정답:
Explanation:
The correct answers are A and C. Versa supports upgrading deployed VOS branch devices either directly on the VOS appliance or centrally through Versa Director. The Director-based method is performed from the Administration > Appliances area: Versa documentation says to select one or more Controller nodes or VOS devices, click the Upgrade Selected Appliances icon, choose the software image package, and proceed with the appliance upgrade. The same upgrade procedure is referenced for remaining VOS branch devices, including the option to upgrade branches individually or all at once.
A CLI-based upgrade using a software .bin package is also a valid operational method when the image is copied to the device and installed locally, particularly for controlled or recovery-style maintenance.
Option B is not the best answer for already deployed branch upgrades because the Preferred Software Version field applies to zero-touch provisioning; Versa states that during ZTP, Director upgrades a branch to the preferred version if applicable. That setting influences onboarding behavior, not the normal upgrade workflow for already deployed branches.
Option D is incorrect because System > Director Upgrade is used to upgrade the Versa Director node itself, not VOS branch appliances.

Question No : 7


You configured Direct Internet Access on your Versa branches using the workflow template.
Which statement is true in this scenario?

정답:
Explanation:
The correct answer is C. In Versa Secure SD-WAN, Direct Internet Access, or DIA, provides local internet breakout from the branch rather than backhauling internet-bound traffic through a hub. Versa design documentation explains that the DIA architecture creates an internal connection between the tenant VRF and the WAN transport VR and uses CGNAT to translate internet-bound LAN traffic to the public IP address associated with the WAN transport interface. It specifically states that the main DIA components include the CGNAT function for translating internet-bound traffic and that DIA is configured using Director Workflows when configuring tunnels.
When the workflow template is used and the DIA option is selected for the internet breakout tunnel, Director automatically builds the required DIA infrastructure, including the NAPT/CGNAT configuration associated with the internet-facing transport network. This is why manual creation of the CGNAT pool and rule is not required in the workflow-based method.
Option A describes a manual configuration approach, not the workflow-generated behavior.
Option B is incorrect because NAT must be associated with the internet-facing breakout path, not simply the LAN interface.
Option D is incorrect because DIA normally requires address translation for LAN users accessing the public internet.

Question No : 8


Examine the exhibit below.



As an administrator of a Versa Secure SD-WAN, you are asked to find the current bandwidth of each WAN circuit used for SD-WAN connectivity in a branch, but the Director is not displaying any information for the WAN circuits.
In this scenario, what should be done to get the graph populated for all WAN circuits?

정답:
Explanation:
The correct answer is B. The exhibit shows the branch interface summary in Versa Director with a Live Data column. To populate real-time bandwidth graphs for WAN circuits, the administrator must select Live Data for the WAN interfaces that need to be monitored. Versa monitoring documentation states that, from a Director node, you can monitor VOS devices and organizations, and that Director, together with Versa Analytics, can poll VOS devices in real time to understand what is happening on the devices. This real-time information can be displayed to assist with troubleshooting.
Because the question asks for the current bandwidth of each WAN circuit, historical analytics alone is not sufficient. The dashboard must poll live statistics from the selected WAN circuits. In the exhibit, not all WAN interfaces appear to have Live Data selected; therefore, the graph is not populated for all circuits. Refreshing the page does not enable polling and will not solve the missing data condition. Selecting only MPLS would populate only the MPLS circuit, not all WAN circuits. Unselecting and reselecting only the INET circuit would affect only that one interface. Therefore, Live Data must be selected for all WAN circuits whose current bandwidth should be displayed.

Question No : 9


A customer has purchased 10 Versa SD-WAN licenses. In this scenario, which statement is correct?

정답:
Explanation:
The correct answer is C. In Versa Secure SD-WAN, licensing and device management are centralized through Versa Director, not directly through the Controller. During zero-touch provisioning and staging, the branch device is brought under centralized management, and Director pushes the required staging and operational configuration. Versa staging documentation explains that during Stage 2 and Stage 3, Versa Director pushes configuration to the branch device, and after Stage 3 the branch becomes fully operational as part of the customer SD-WAN network.
Versa monitoring documentation also shows that the Director node provides license visibility, specifically stating that the Director monitoring view includes a License pane that displays information about the licenses installed on the VOS devices managed by the Director node. This confirms that license administration is handled from Director, not from the Controller. The Controller is responsible for SD-WAN control-plane functions and tunnel connectivity, but it is not the primary system for managing customer license subscriptions.
Option A is incomplete because the practical operational model is not simply receiving individual soft licenses.
Option B incorrectly implies licenses are preloaded on physical CPEs as the key licensing method.
Option D is incorrect because ZTP management and license subscription handling are not performed by the Controller.

Question No : 10


Examine the exhibit below.



You are configuring an IPsec tunnel towards a non-SD-WAN site over the INET Transport-VR. The site IP address is 10.1.1.1. This tunnel is for traffic between the 192.168.100.0/24 and the 192.168.200.0/24 LAN networks. The tunnel does not establish.
Referring to the exhibit, which statement is correct?

정답:
Explanation:
The correct answer is A. The exhibit shows that the IPsec VPN is being configured with Tunnel Routing Instance: XIAN-Control-VR. However, the question states that the tunnel is toward a non-SD-WAN site over the INET-Transport-VR. For a site-to-site IPsec tunnel, the tunnel routing instance must match the routing instance used to reach the peer public IP address. In this case, the remote non-SD-WAN peer is 10.1.1.1, and the intended underlay transport is INET-Transport-VR, not the Control VR.
Versa troubleshooting documentation explains that routing instances are used to define where traffic is sourced and forwarded. For example, configuration examples select routing instances when enabling services or initiating tests, and traffic must use the correct WAN or transport routing instance to reach the remote endpoint. Versa branch troubleshooting also emphasizes that after transport connectivity is available, the branch establishes IKE-based IPsec connectivity; if that connectivity fails, the IPsec-related interface remains down.
Changing the routing instance to global would not be correct because the intended path is specifically INET-Transport-VR. A higher precedence value is not required to establish the tunnel. The policy selector shown already defines local-to-remote interesting traffic, and the key failure is the incorrect tunnel routing instance.

Question No : 11


You are asked to deploy a Versa Secure SD-WAN branch for 1000 locations. You need to profile the branches based on common deployment requirements.
In this scenario, which three configuration objects would be shared by multiple appliances? (Choose three.)

정답:
Explanation:
The correct answers are A, B, and D. For large-scale Versa Secure SD-WAN onboarding, common configuration is reusable through templates and grouping. A device template, also known as a post-staging template, provides the common base configuration that is applied to multiple VOS branch appliances. Versa documentation repeatedly shows configuration tasks being performed under Templates > Device Templates, where an organization is selected and the post-staging template is opened in Appliance view for common configuration.
A device group is also shared by multiple appliances because it groups devices that should receive the same template associations and common service behavior. This is the proper way to profile many branches with similar deployment requirements. Service templates are also shared objects. They are used to apply service-specific configurations, such as SD-WAN traffic steering, application steering, QoS, security, or other common services, across devices. Versa SD-WAN design documentation explains that application-steering templates automate business-intent policies and simplify management by combining application classification, forwarding-class mapping, and SD-WAN policy logic in a reusable template.
A workflow device is device-specific, and device bind data contains site-specific values such as interface addressing, gateways, VLANs, and other per-branch parameters. Therefore, those are not the shared configuration objects.

Question No : 12


Examine the exhibit below.



An SD-WAN administrator has configured Direct Internet Access (DIA) for INET and INET-2 and wants to use SaaS Application Monitoring and SD-WAN policies to steer certain applications to the best Internet path on a certain VOS device.
Which two statements are true regarding the configuration shown in the exhibit? (Choose two.)

정답:
Explanation:
The correct answers are B and D. In the exhibit, the Next-Hop Selection Method is configured as Load Balance, and both INET and INET-2 have the same next-hop priority value of 1. Versa SD-WAN guidance states that load balancing between WAN paths is achieved by configuring at least two circuits with equal priority. Therefore, when both INET and INET-2 satisfy the SLA requirements, sessions can be load-balanced across those two internet circuits.
Option D is also correct because the exhibit shows SLA Violation Action: Forward. This means that if no next hop is SLA-compliant, the VOS device is still allowed to forward traffic instead of dropping it. This behavior is consistent with Versa SD-WAN traffic-steering concepts, where forwarding profiles define circuit or path priorities, connection methods, load-balancing behavior, and SLA handling for traffic that matches an SD-WAN policy.
Option A is incorrect because the exhibit does not use the Automatic next-hop selection method. Versa’s performance-based SaaS optimization uses monitoring metrics to select the best path when configured for automatic/performance-based selection, but this exhibit shows Load Balance instead.
Option C is not the best answer because LTE has lower priority 2 and would be considered only after the higher-priority INET and INET-2 paths are unavailable or unusable, not merely when one INET circuit fails.

Question No : 13


Examine the exhibit below.



Referring to the exhibit, which two statements are correct? (Choose two.)

정답:
Explanation:
The correct answers are A and B. In the exhibit, the LAN interface shows a fixed VLAN ID value of 100. Because this value is directly configured in the template rather than represented as a per-device variable, every branch that uses this template will receive the same LAN VLAN ID. This supports option A. Versa configuration examples show that VLAN-tagged interfaces are created by defining logical units with a vlan-id, and organizations then use those tagged interfaces for traffic identification and routing services.
For the MPLS WAN network, the VLAN ID field is shown as a variable or bind-data style value rather than a fixed number. This allows each branch device to receive a different MPLS VLAN ID during onboarding, depending on the branch-specific values supplied in the workflow or device bind data. Therefore, branches can have separate VLAN IDs on the MPLS WAN transport, which supports option B. Versa SD-WAN troubleshooting output also shows WAN interfaces as logical VNI sub interfaces, such as vni-0/1.0 and vni-0/2.0, mapped to SD-WAN transport networks like INET and MPLS.
Option C is incorrect because an INET interface can be untagged, commonly represented with VLAN ID 0.
Option D is incorrect because the MPLS VLAN field is intentionally parameterized, not incorrectly configured.

Question No : 14


Examine the exhibit below.



Which two statements correctly explain the routing shown in the exhibit. (Choose two.)

정답:
Explanation:
The correct answers are A and C. The route table shown in the Versa SD-WAN design documentation includes a default route, 0.0.0.0/0, with next hop 169.254.0.2 and exit interface tvi-0/603.0. A default route is used when no more specific route exists in the routing table, so any unknown IPv4 unicast destination will follow that active default route through the tvi-0/603 interface. This directly supports option C.
The same design context describes local or central internet breakout, where Director workflows create TVI-based connectivity for breakout or gateway-style forwarding. In Versa SD-WAN, TVI interfaces are commonly used as internal virtual tunnel interfaces between routing instances, such as between a tenant LAN VR and a transport or breakout VR. The documentation also describes virtual TVI interface pairs being created by Director workflows between VRs for gateway routing use cases. Therefore, option A is also correct: tvi-0/603 is paired with another interface in another VR to support the default-route forwarding path.
The IP address is not shown as misconfigured; 169.254.x.x addressing is commonly used for point-to-point internal TVI links. The route is also not a blackhole route, because it has an active next hop and an exit interface.

Question No : 15


You are onboarding a branch with one WAN and one LAN interface. After a successful branch activation, the branch is not able to reach the Versa Controller. You realize that the WAN gateway IP address originally entered under the Device Bind Data menu in Versa Director is incorrect.
Which action will you perform to solve the problem?

정답:
Explanation:
The correct action is to update the WAN gateway IP address in Device Bind Data and onboard the branch appliance again. Device Bind Data supplies site-specific values, such as WAN interface addressing and gateway information, that are merged with the workflow and template configuration during onboarding. If the wrong WAN gateway is entered, the branch may activate successfully from a workflow perspective, but the resulting WAN routing configuration is incorrect. As a result, the branch cannot establish proper transport reachability to the Controller. Versa troubleshooting documentation explains that, after establishing transport connectivity from a branch to a Controller, at least one WAN interface must be available, and the branch then establishes IKE-based IPsec connectivity to the Controller. If that IKE/IPsec connectivity fails, the Controller-facing ptvi interface remains down.
Changing the configuration only from the Appliance context is not the best answer because the incorrect value originated in the bind-data source used for provisioning. Modifying it manually from the branch CLI is also not recommended because the device is managed by Versa Director and template-driven configuration. Resetting the device does not automatically discover or “ping” the correct gateway. The correct remediation is to fix the bind data and repeat onboarding so the branch receives the correct generated configuration.

 / 2
Versa Networks