Designing and Implementing Enterprise Network Assurance 試験
最新更新時間: 2026/09/21
【秋学習応援セール|10月限定キャンペーン】:300-445 最新真題を買う時、日本語版と英語版両方を同時に獲得できます。
実際の問題集を練習し、試験のポイントを了解し、テストに申し込むするかどうかを決めることができます。
さらに試験準備時間の35%を節約するには、300-445 問題集を使用してください。
Question No : 1
You have been tasked with creating a dashboard in your organization’s Observability platform. This dashboard should have data that is streamed in real-time and used to populate data for tables, graphs, charts, and other formats.
What kind of integration should you use?
正解:
Explanation:
Within the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) framework,
the transition from "polling" to "streaming" is a major architectural shift. To populate real-time dashboards in external observability platforms like Grafana, Splunk, or AppDynamics, the architect should utilize the Open Telemetry (OTel) integration (Option B).
Thousand Eyes for Open Telemetry is a push-based API built on the standardized Open Telemetry Protocol (OTLP). Unlike traditional REST API polling (Option A), which retrieves data at fixed intervals and can be subject to rate limiting and latency, the OTel integration allows Thousand Eyes to stream granular network metrics as they are collected. These metrics―including latency, loss, jitter, and HTTP response times―are exported in a standardized format that is natively understood by modern observability backends. This allows the platform to populate complex visualizations such as time-series graphs, heatmaps, and multi-metric tables in near real-time, providing a "single pane of glass" view that correlates network performance with application and infrastructure telemetry.
A key advantage of the OTel approach is data portability and correlation. By applying metadata tags to Thousand Eyes tests, the data can be filtered and categorized within the external dashboard to match the organization's business logic (e.g., grouping by region or application tier). This enables SREs and NetOps teams to quickly identify if a performance dip in an application dashboard correlates with a spike in internet latency measured by Thousand Eyes. Options C and D do not provide the streaming data pipeline required for real-time external dashboard population. Thus, Open Telemetry is the definitive choice for high-fidelity, real-time observability integration.
Question No : 2
Your organization wants to be notified of an event as soon as it is triggered by an alert threshold. This notification should be sent to your ITSM and generate an incident so it can be responded to appropriately.
What kind of integration should you use?
正解:
Explanation:
In the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) curriculum, the
objective of modern network assurance is to bridge the gap between "visibility" and "action". When an organization requires an automated workflow to handle network performance anomalies, the most efficient architecture is the native ServiceNow Integration (Option A). This integration is categorized as a "Custom-Built" or native integration within the Thousand Eyes platform, designed specifically to facilitate the delivery of direct notifications into a ServiceNow account.
According to the ENNA implementation standards, the Thousand Eyes ServiceNow integration utilizes the ServiceNow Incident Management module. When a predefined alert rule (such as a 5% packet loss threshold on a critical SaaS path) is violated, Thousand Eyes triggers an event and immediately pushes the alert data to ServiceNow via an OAuth-authenticated connection. Within ServiceNow, this data is used to automatically generate an Incident, complete with relevant metadata such as the test name, agent location, and the specific metrics that triggered the violation. This automation eliminates the manual overhead of "copy-pasting" alert details from a monitoring dashboard into a ticketing system, thereby significantly reducing the Mean Time to Identification (MTTI).
While Custom Webhooks (Option C) can achieve a similar result by sending JSON payloads to a REST API, they require additional development effort to parse the data on the receiver side. The native ServiceNow integration provides a pre-configured template that maps Thousand Eyes alert fields directly to ServiceNow incident fields, offering a "one-click" setup experience that is preferred for enterprise-grade deployments. Options B and D are irrelevant for the specific goal of ITSM incident generation. Therefore, for direct ITSM notification and incident creation, the native ServiceNow Integration is the verified recommendation.
Question No : 3
What is an important consideration when choosing a time period for collecting data to establish a baseline for interface utilization on a critical network link?
正解:
Explanation:
Establishing an accurate baseline is a cornerstone of the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) methodology. A baseline must represent the "typical" behavior of the network across its standard operating cycle to be useful for anomaly detection and capacity planning. When monitoring interface utilization on a critical link, it is vital to capture both peak and off-peak traffic patterns (Option C).
Most enterprise networks exhibit cyclical traffic patterns, often referred to as "diurnal" cycles, where utilization spikes during business hours (peak) and drops significantly at night or on weekends (off-peak). If an engineer only collects data during the lowest volume period (Option A), the baseline will be unrealistically low, leading to "false positive" alerts when normal business traffic returns. Conversely, only capturing peak data might hide background synchronization tasks or backup windows that occur during off-hours.
By selecting a representative time period―typically one full week or a month―the engineer ensures the baseline accounts for variations such as Monday morning "logon storms," mid-week steady states, and weekend maintenance. This comprehensive view allows the assurance platform (such as Cisco Catalyst Center or Thousand Eyes) to calculate a standard deviation and establish dynamic thresholds. If utilization deviates from these historically representative norms, the system can trigger an alert based on a true anomaly rather than a predictable daily surge. Aligning with a financial year (Option B) is irrelevant to technical performance, and limiting the data (Option D) compromises the baseline's statistical validity.
Question No : 4
A network administrator wants to establish a baseline for CPU utilization on their core routers.
Which data source would be MOST appropriate for this purpose?
正解:
Explanation:
In the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) framework, baselining is the process of establishing a "normal" performance profile for network infrastructure to enable the detection of anomalies. When the metric of interest is the internal health of a physical device, such as CPU utilization on a core router, SNMP (Simple Network Management Protocol) is the industry-standard data source.
SNMP provides direct visibility into the device's control plane and hardware performance. By polling specific Object Identifiers (OIDs) from the router's Management Information Base (MIB), a monitoring system like Cisco Catalyst Center or a third-party NMS can collect granular data on CPU cycles, memory allocation, and temperature. This "inside-out" telemetry is essential for baselining because it reflects the actual resource consumption of the router during various traffic loads.
Conversely, Thousand Eyes tests (Options A, B, and D) provide "outside-in" synthetic data. While DNS resolution time (Option A), HTTP response times (Option B), and Path Visualization (Option D) are excellent for measuring end-to-end service delivery and network transit health, they do not report on the router's internal hardware state. For instance, a router could have 99% CPU utilization (indicating a potential crash), yet a Thousand Eyes path test might still show a "green" path if the data plane (ASICs) is still forwarding packets efficiently. Therefore, to establish a reliable baseline for hardware-specific metrics like CPU, SNMP data (Option C) is the only appropriate source among the choices.
Question No : 5
The network team has deployed Webex RoomOS Endpoint Agents and integrated Webex Control Hub with Thousand Eyes. The VoIP team wants to know which metrics they can collect from the Webex Control Hub view.
Where does the VoIP team find the network data?
正解:
Explanation:
According to the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) curriculum, the integration between Thousand Eyes and Webex Control Hub provides a streamlined troubleshooting experience for collaboration services. For the VoIP team to access the specific Thousand Eyes network telemetry―such as latency, loss, and jitter―they must navigate to the Network Path (Option B) section within the Troubleshooting tab of the Control Hub.15
The Network Path visualization is a direct result of the Thousand Eyes Endpoint Agent data being pulled into the Webex interface.16 When a user or RoomOS device experiences poor audio or video quality during a meeting, the Control Hub's troubleshooting view displays a "Network Path" line under the participant's details.17 By clicking on this line, the VoIP team can see a hop-by-hop breakdown of the entire route from the collaboration device to the Webex media node. This view highlights specific hops where performance is "Poor" (red), "Fair" (yellow), or "Good" (green) based on predefined thresholds for latency (>400ms) or loss (>5%).
While "Devices" (Option A) is where the agents are activated, and "Users" (Option C) allows for selecting a specific participant, the actual telemetry metrics and the visualization of the network route are strictly located in the Network Path view. This integration eliminates the need for the VoIP team to leave the Webex environment for initial triage, as they can identify if a problem is local to the branch office or deep within a service provider's network directly from the "Network Path" dashboard.
Question No : 6
What advantage does the integration of Thousand Eyes with Cisco technologies offer for troubleshooting?
正解:
Explanation:
The Designing and Implementing Enterprise Network Assurance (300-445 ENNA) certification emphasizes that the primary value proposition of the Cisco "Assurance Stack" is the reduction of Mean Time to Identification (MTTI) and Mean Time to Resolution (MTTR). The integration of Thousand Eyes across Cisco's portfolio―including Catalyst, Meraki, and SD-WAN―allows for quick identification and resolution of performance issues (Option D).12
By embedding Thousand Eyes agents into the existing network infrastructure, Cisco enables "end-to-end visibility" that spans domains the enterprise traditionally does not control, such as the public internet and SaaS environments.13 During troubleshooting, this cross-platform visibility allows network engineers to immediately correlate internal network health (from Catalyst Center or Meraki Dashboard) with external path visualization (from Thousand Eyes). For example, when a user experiences poor video quality in a Webex meeting, the integration allows the engineer to "cross-launch" from the Webex Control Hub directly into a Thousand Eyes path view.14 This pinpoint accuracy avoids the "blame game" between network, application, and ISP teams by providing a "single source of truth" regarding where the packet loss or latency is occurring.
While some automation exists (Option C), the core benefit isn't automatic configuration changes based on feedback, but rather providing the actionable insights required for manual or policy-based remediation. Similarly, while it streamlines data gathering, its ultimate purpose is the speed of resolution in complex, hybrid environments.
Question No : 7
What type of data does Thousand Eyes use to diagnose when integrated with Cisco Secure Client?
正解:
Explanation:
Under the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) guidelines, the integration between Thousand Eyes and Cisco Secure Client (formerly AnyConnect) is designed to provide visibility into the hybrid workforce experience. The integration primarily leverages network performance data from the user's device (Option C) to diagnose connectivity and application issues.
This data is collected by the Thousand Eyes Endpoint Agent, which is deployed as a module within the Cisco Secure Client.10 The agent captures real-time telemetry from the user's laptop or workstation, including Wi-Fi signal strength, CPU and memory utilization, and local network gateway latency.
Specifically, for remote users, it monitors the health of the VPN tunnel and the performance of applications as seen from the end-user's vantage point.
When a user reports a "slow application," this integrated telemetry allows IT teams to determine if the root cause is the user's home Wi-Fi, a saturated VPN concentrator, or an issue within the ISP underlay. The agent performs Automated Session Testing (AST), which maps the network path as soon as a user joins a critical meeting or accesses a SaaS tool, providing a granular view of every hop between the device and the service destination. Unlike hardware configuration data (Option A) or behavioral analytics (Option B), the focus here is strictly on the network performance metrics that impact digital experience.
Therefore, the collection of device-centric network performance data is the core function of the Cisco Secure Client and Thousand Eyes integration.
Question No : 8
What is the primary purpose of integrating Thousand Eyes with Meraki?
正解:
Explanation:
The Designing and Implementing Enterprise Network Assurance (300-445 ENNA) framework highlights the integration between Thousand Eyes and Cisco Meraki as a solution for "cross-domain assurance".5 The primary purpose of this integration is to monitor external applications and services from SD-WAN sites (Option B).
In a distributed Meraki environment, IT teams often struggle with visibility into the "Internet as a WAN," where performance issues may occur outside the local network perimeter. By embedding Thousand Eyes Enterprise Agents natively within Meraki MX appliances, organizations can bridge the gap between internal LAN metrics and external service health.6 This integration allows for proactive monitoring of SaaS platforms (like Microsoft 365, Salesforce, and Webex) and other public-facing dependencies using synthetic probes. It complements the native Meraki Insight (MI), which provides passive monitoring of real user traffic, by adding active path visualization and hop-by-hop analysis across the Internet.
Key advantages of this integration include:
One-Click Activation: Enabling the Thousand Eyes agent directly from the Meraki Dashboard without additional hardware.7
Pre-configured Templates: Using built-in test templates for common SaaS applications to accelerate troubleshooting.8
Isolation of Fault Domains: Quickly determining if a user's lag is caused by a local Wi-Fi issue (via Meraki wireless metrics) or an ISP routing problem (via Thousand Eyes path data).9
While Thousand Eyes does provide visibility for VPN and security, Options A, C, and D are not the primary focus of the specific Meraki-Thousand Eyes integration architecture, which is centered on extending application performance assurance to distributed branch locations.
Question No : 9
What type of agent is typically installed on Cisco SD-WAN devices as part of the Thousand Eyes integration with vManage?
正解:
Explanation:
In the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) curriculum, the integration of Thousand Eyes with the Cisco SD-WAN fabric is a cornerstone of modern wide-area network visibility. The primary agent type used in this native integration is the Enterprise Agent (Option C).
According to the ENNA implementation guidelines, Thousand Eyes Enterprise Agents run as containerized applications directly on the Cisco IOS XE software stack (version 17.6.1 and later) of supported hardware, such as Cisco Catalyst 8000 Edge Platforms and ISR 4000 Series routers.3 This deployment is orchestrated centrally through Cisco Catalyst SD-WAN Manager (formerly vManage), which handles the lifecycle management, including downloading the Docker-based agent image from the Cisco software repository and pushing the initial configuration to the branch edge devices.4
Once deployed, these Enterprise Agents function as internal vantage points that can measure performance across both the underlay transport and the SD-WAN overlay. By placing the agent on the router, engineers can execute synthetic tests to monitor mission-critical SaaS applications or data center services directly from the branch's perspective, avoiding the need for extra hardware probes at each site. This "agent-on-router" architecture significantly reduces both CapEx and OpEx while providing high-fidelity network intelligence into ISP peering, regional outages, and fabric health.
Cloud Agents (Option A) are managed by Cisco in global data centers and cannot be "installed" on customer edge routers.
Endpoint Agents (Option D) are designed for user workstations or laptops and do not provide the infrastructure-level visibility required for SD-WAN transport monitoring.
Browser Agent (Option B) is not a specific standalone agent type in this context; rather, browser-level testing is a capability often performed by Endpoint or Enterprise Agents.
Therefore, the Enterprise Agent is the correct verified agent type for Cisco SD-WAN vManage integration.
Question No : 10
Thousand23Eyes WAN Insights integrates with Cisco SD-WAN to provide visibility into network performance and generate path recommendations.
Which two data sources from the SD-WAN environment are e25ssential for WAN Insights to function? (Choose two)
正解:
Explanation:
The architecture for Designing and Implementing Enterprise Network Assurance (300-445 ENNA) specifies that Thousand Eyes WAN Insights relies on deep integration with the Cisco SD-WAN management stack. To generate its predictive path recommendations, the platform must ingest specific telemetry data that reflects both the network's behavior and the applications traversing it.
The first essential data source is historical network performance metrics collected by vAnalytics (Option B). Before WAN Insights can be activated, vAnalytics must be enabled to collect and enrich raw network telemetry from the edge routers.34 This data includes granular metrics for every SD-WAN tunnel, such as packet loss, latency, and jitter.35 WAN Insights analyzes these historical trends to forecast future path quality and determine which transport circuits are most likely to meet application SLAs over a long-term period.
The second essential data source is application traffic flow data (Option D). WAN Insights must understand which applications are currently active in the fabric to prioritize recommendations for "business-critical" services like Office 365, Webex, or custom internal apps.38 This information is ingested as flow records from the SD-WAN data plane and categorized based on the Application Lists defined in Cisco Catalyst SD-WAN Manager (vManage).
Options A and E are configuration or logging data that, while useful for general management, are not the raw telemetry inputs used by the WAN Insights predictive engine. Option C is incorrect because WAN Insights explicitly uses infrastructure telemetry rather than Thousand Eyes agent-based synthetic data for its SD-WAN fabric calculations. By combining vAnalytics performance metrics and application flow data, WAN Insights can provide the "Predictive Path Recommendatio41ns" that are a hallmark of modern network assurance.
Question No : 11
A network administrator observes a recurring pattern in their Cisco SD-WAN: during peak business hours, users at a specific branch office experience poor voice call quality, characterized by choppy audio and delays.6 The administrator suspects that network congestion is contributing to this issue and wants to leverage Thousand Eyes WAN Insights to improve the situation proactively.
Which capability of WAN Insights is most relevant to this scenario?
A. Monitoring the public internet paths to the voice call service provider and identifying outages or performance bottlenecks.7
B. Analyzing historical SD-WAN performance data during peak hours and recommending alternative paths that prioritize voice traffic based on its SLA.
C. Generating synthetic voice traffic to proactively test network paths and identify potential congestion points during peak hours.8
D. A set of network management tools that leverage SNMP and flow protocols into a single dashboard.
E. Providing real-time alerts on security threats targeting voice traffic within the SD-WAN.9
正解: B
Explanation:
According to the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) curriculum, Thousand Eyes WAN Insights is a predictive analytics solution designed to transform network management from a reactive to a proactive model.10 In the scenario provided, the voice quality issues are recurring and peak-hour dependent, indicating a need for optimization rather than just standard real-time alerting.11
The most relevant capability for this scenario is analyzing historical SD-WAN performance data to generate path recommendations (Option B). WAN Insights integrates with Cisco Catalyst SD-WAN Manager (vManage) and vAnalytics to ingest massive volumes of telemetry.12 It uses advanced statistical models to analyze the performance of all active circuits (MPLS, Internet, etc.) over time. If the system identifies that a different available path consistently delivers a higher Quality of Experience (QoE) or better adherence to the voice SLA during those peak windows, it generates a recommendation to adjust the Application-Aware Routing (AAR) policy.1314
This predictive approach allows the administrator to fine-tune network policies in advance, ensuring that sensitive traffic like voice is automatically rerouted to the most stable path before the congestion impacts the users. Option A describes standard Thousand Eyes synthetic testing, while Option C is incorrect because WAN Insights specifically uses existing SD-WAN telemetry rather tha15n generating its own synthetic voice16 probes. Option D and E describe general NMS or security features not specific to WAN Insights' predictive mission. Thus, the proactive recommendation of alternative paths based on historical SLA adherence is the core function of WAN Insights for improving voice quality.171819
Question No : 12
What is a primary advantage of passive monitoring over active monitoring?
正解:
Explanation:
In the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) architecture, a critical design consideration is the impact of the monitoring solution on the production environment. The primary advantage of passive monitoring (Option B) is its non-intrusive nature; it provides insights into network performance and traffic composition without injecting additional "synthetic" overhead into the data plane.
Passive techniques―such as Cisco Meraki Insight (MI), NetFlow, and SNMP―rely on the telemetry generated by existing user traffic or the device's own control plane. For example, Meraki Insight analyzes HTTP/S flows as they naturally pass through a Meraki MX appliance to derive application performance scores, rather than sending separate probes.5 This ensures that the monitoring tool itself does not consume bandwidth or contribute to network congestion, which is particularly vital in bandwidth-constrained branch environments or on high-utilization links.
In contrast, active monitoring (Options A and C) requires the deliberate generation of synthetic traffic, which can potentially skew results if the volume is too high or if the network is already at capacity. While active monitoring is essential for proactive troubleshooting (measuring performance before users complain), passive monitoring is the preferred method for long-term historical analysis of real user experience and infrastructure utilization because it captures what is actually happening on the wire. Option D is a shared capability; both types can measure specific services, but only passive monitoring does so while remaining transparent to the network load. Therefore, the lack of added traffic is the definitive advantage of the passive approach.
Question No : 13
Which of the following is an example of active monitoring in network performance management?
正解:
Explanation:
Within the framework of Designing and Implementing Enterprise Network Assurance (300-445 ENNA), network monitoring is categorized into two primary methodologies: active and passive monitoring.1 Active monitoring (Option C) is characterized by the generation of synthetic or "probes" traffic specifically designed to measure network performance.2 These probes simulate real-world user activity, such as HTTP requests, DNS queries, or ICMP pings, to baseline performance metrics like latency, jitter, and packet loss.
The core benefit of the active approach is its independence from actual user traffic. By sending a continuous ping or synthetic HTTP probe, an engineer can verify path availability and performance even during off-peak hours when no real users are on the network. In the context of Cisco Thousand Eyes―a central platform in the ENNA certification―this is the primary mode of operation for Cloud, Enterprise, and Endpoint agents. For instance, a Thousand Eyes network test proactively sends packets to a target IP or URL to visualize the hop-by-hop underlay and overlay paths.
Conversely, options A, B, and D represent passive monitoring techniques. Passive monitoring involves observing and analyzing traffic that is already traversing the network.3 Methods such as SNMP (Option A) provide device-level health data like CPU load and interface utilization, while packet captures (Option B) and NetFlow (Option D) analyze the characteristics of existing user flows to determine top talkers or traffic patterns. While passive monitoring is excellent for volume and utilization analysis, it lacks the proactive capability to test a path's performance before a user encounters a failure. Therefore, sending a synthetic probe like a continuous ping is the definitive example of active monitoring.
Question No : 14
A network engineer needs to monitor the performance of a business-critical web application accessed by remote employees connecting through a Cisco AnyConnect VPN.
Which two agent deployment methods are most suitable for this scenario? (Choose two)
正解:
Explanation:
For the Designing and Implementing Enterprise Network Assurance (300-445 ENNA) exam, monitoring remote workforces requires a strategy that captures both the user's local environment and the regional internet health. In a scenario involving Cisco AnyConnect VPN, the "last mile" connectivity of the employee is often the most significant variable in application performance.
Utilizing the Thousand Eyes Endpoint Agent (Option D) is the most effective way to monitor this environment. Because the agent resides directly on the remote employee's machine, it can monitor the performance of the web application both "inside" and "outside" the VPN tunnel. It provides visibility into the local Wi-Fi signal strength, the health of the AnyConnect client, and the latency experienced as traffic traverses the VPN headend. This allows engineers to differentiate between a slow home internet connection and an issue with the VPN concentrator.
Deploying Thousand Eyes Cloud Agents (Option A) serves as a critical baseline. By running tests from Cloud Agents in the same regions as the remote employees, the engineer can determine if the "internet" in that region is healthy. If a Cloud Agent in London shows a perfect response time while an Endpoint Agent in London shows high latency, the engineer can immediately isolate the problem to the user's specific setup or the VPN path, rather than a regional ISP outage.
Other options are less suitable for monitoring the remote employee's experience:
AppDynamics (Option B) provides server-side code visibility but cannot see the user's home Wi-Fi or local network path.
Enterprise Agents on the VPN concentrator (Option C) can monitor the path from the data center to the app, but they cannot see the path from the user to the concentrator.
Enterprise Agents in the data center (Option E) provide an "inside-out" view of the app's health but miss the entire remote access experience.
Question No : 15
A network engineer wants to measure their SD-WAN performance metrics.
Which agent deployment method is most suitable for this scenario?
正解:
Explanation:
In the context of Designing and Implementing Enterprise Network Assurance (300-445 ENNA), understanding the visibility gap in SD-WAN environments is essential. While SD-WAN controllers provide native visibility into the overlay network (the logical IPsec tunnels and fabric health), they often lack granular insight into the physical transport or underlay network provided by ISPs or MPLS circuits.
According to the ENNA architecture guidelines, the most suitable method for measuring true SD-WAN performance is to install an agent on the underlay network (Option D). By deploying Thousand Eyes Enterprise Agents directly on the transport-facing interfaces (Transport VPN0 in Cisco SD-WAN terminology), engineers can perform hop-by-hop path visualization and measure metrics like packet loss, latency, and jitter across the actual provider path. This is critical because performance degradation in the overlay is almost always a symptom of an issue in the underlay, such as BGP routing instabilities or physical link congestion at an ISP peering point.
Deploying agents on the overlay (Option A) only measures the performance of the tunnel itself, which may hide specific hop-level failures occurring in the public internet. Installing an agent on the LAN (Option C) or DMZ (Option B) adds local network noise to the metrics, making it harder to isolate if a problem exists within the corporate office or the service provider network. By focusing on the underlay, the engineer ensures they have the "internet intelligence" required to hold service providers accountable to SLAs and quickly resolve connectivity issues that impact the SD-WAN fabric.