CCNP Architecture Practice Question
A network architect is designing a Cisco SD-Access fabric for a hospital campus. The hospital requires that guest wireless users be allowed access only to the internet, while clinical staff devices must reach internal EHR servers. The fabric uses Cisco DNA Center and Cisco Identity Services Engine for policy. Which fabric component enforces the group-based policy between these user groups?
⚠ Common exam trap
The trap here is assuming the controller or the underlay enforces user policy, when enforcement actually occurs on the fabric edge node through group-based ACLs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The fabric edge node applying Cisco TrustSec group-based access control lists
Group-based policy in a Cisco SD-Access fabric is enforced at the fabric edge node using Cisco TrustSec security group tags and scalable group ACLs, with group membership and policy defined in Cisco Identity Services Engine. This lets the hospital block guest-to-EHR flows while permitting clinical staff access, without redesigning VLANs or subnets for each user category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Cisco DNA Center Intent API translating business intent into device configuration
Why it's wrong here
DNA Center is the management and automation platform that translates intent into fabric device configuration, but it does not sit in the data path. Once it provisions the edge nodes, policy enforcement happens on the network devices, not in the controller. Relying on DNA Center itself for per-packet enforcement of guest versus clinical traffic would fail because management-plane systems do not forward or filter user traffic.
- ✗
The fabric control plane node running LISP map-server functions
Why it's wrong here
The control plane node maintains the LISP mapping database of endpoint-to-routing-locator associations so fabric devices can resolve destinations. It does not inspect or enforce traffic policy between endpoint groups; it only provides reachability information. In this hospital scenario, it would help staff devices locate EHR servers, but it would not prevent guest users from reaching those servers, so it is not the enforcement point.
- ✗
The fabric intermediate node forwarding VXLAN-encapsulated traffic between edge nodes
Why it's wrong here
Intermediate nodes are underlay routers or switches that transport VXLAN-encapsulated packets between fabric edge nodes; they operate on the outer header and do not inspect the original endpoint traffic or its security group tags. They provide scalable transit but no policy decisions. In the hospital design, an intermediate node would forward guest traffic toward an EHR server just as readily as clinical traffic, so it cannot enforce the isolation requirement.
- ✓
The fabric edge node applying Cisco TrustSec group-based access control lists
Why this is correct
Fabric edge nodes encapsulate traffic in VXLAN and enforce group-based policy using Cisco TrustSec security group tags and scalable group ACLs derived from ISE policy. When a guest wireless user tries to reach an EHR server, the ingress edge node drops the packet based on the source and destination security group tags. This directly delivers the required isolation between guest and clinical traffic in the SD-Access fabric.
Visual reference
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.