Courseiva
mediumMultiple Choice

350-401 Practice Question: Consider the following SD-WAN configuration…

Consider the following SD-WAN configuration snippet on a Cisco IOS-XE router:

interface GigabitEthernet0/0/1
 ip address 10.1.1.1 255.255.255.0

tunnel-interface

encapsulation ipsec

color biz-internet

no allow-service bgp

allow-service dhcp allow-service dns allow-service icmp !

What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the misconception that 'no allow-service bgp' is invalid or that the tunnel-interface configuration only applies to loopback interfaces, when in fact it is a valid command applied to physical interfaces to filter control-plane traffic per transport color.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The interface is configured as an SD-WAN tunnel interface with color biz-internet, allowing DHCP, DNS, and ICMP traffic but blocking BGP.

The configuration applies to a GigabitEthernet interface that is placed into SD-WAN tunnel mode using the 'tunnel-interface' command. The 'color biz-internet' assigns the transport color, and the 'allow-service' and 'no allow-service' commands explicitly control which control-plane services are permitted over the tunnel. DHCP, DNS, and ICMP are allowed, while BGP is explicitly denied, making option A correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The interface is configured as an SD-WAN tunnel interface with color biz-internet, allowing DHCP, DNS, and ICMP traffic but blocking BGP.

    Why this is correct

    This is correct because the `tunnel-interface` command provisions the physical GigabitEthernet interface as an SD-WAN transport tunnel, and the `color biz-internet` attribute designates the WAN transport class. The `allow-service` statement explicitly permits DHCP, DNS, and ICMP while the `no allow-service bgp` line denies BGP, so the interface only carries the listed services and not BGP.

  • ✗

    The interface is configured as a standard WAN interface with IPsec encryption, allowing all services including BGP.

    Why it's wrong here

    This is incorrect because `tunnel-interface` is an SD-WAN-specific configuration that creates a secure tunnel with IPsec encapsulation, not a standard WAN interface. Moreover, the `no allow-service bgp` command explicitly blocks BGP, contradicting the claim that all services are allowed; thus the interface is not a plain IPsec WAN and BGP is specifically denied.

  • ✗

    The configuration enables the interface as a loopback tunnel for OMP traffic only, blocking all other services.

    Why it's wrong here

    This is incorrect because the interface is a physical GigabitEthernet interface, not a loopback interface, and tunnel-interface does not create a loopback. Additionally, the configuration allows DHCP, DNS, and ICMP rather than blocking all other services, and OMP traffic is carried over the tunnel's control plane (DTLS/tLS), not exclusively as the sole service.

  • ✗

    The interface is configured for SD-WAN with color biz-internet, but the 'no allow-service bgp' command is invalid on a tunnel interface.

    Why it's wrong here

    This is incorrect because `no allow-service bgp` is a valid and commonly used command under a `tunnel-interface`; it explicitly removes BGP from the permitted service list on that tunnel. The command is not invalid—it simply ensures BGP is not transported over the SD-WAN tunnel, while other services like DHCP, DNS, and ICMP remain allowed.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.