Which two features are NOT supported when FIPS mode is enabled on an IOS XE SD-WAN device? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: SXP over IPv6, Cisco TrustSec.
Why this is the answer
FIPS (Federal Information Processing Standards) mode enforces strict cryptographic standards, which can limit the availability of certain features. SXP over IPv6 is not supported because FIPS mode on IOS XE SD-WAN devices restricts SXP (Security Group Tag Exchange Protocol) to IPv4 only. Cisco TrustSec is also not supported in FIPS mode because TrustSec relies on certain cryptographic primitives and key management practices that are not compliant with FIPS 140-2 requirements on these platforms. SXP reflectors and Static IP–SGT mapping are generally supported as they don't inherently violate FIPS cryptographic standards. Authentication Key is a generic security mechanism and is not a feature that would be disabled by FIPS mode itself; rather, the strength of the keying material would be mandated.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed