CCNP Virtualization Practice Question
A network architect is designing a Cisco SD-Access fabric. The requirement is to provide secure segmentation for different departments without deploying separate physical networks or traditional VRFs on every switch. Which Cisco SD-Access component provides this segmentation by using a group-based policy model?
⚠ Common exam trap
The trap here is assuming that VRFs are the only way to segment traffic, overlooking the identity-based, group-policy model that SD-Access provides through SGTs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scalable Group Tag (SGT)
Cisco SD-Access uses Scalable Group Tags (SGTs) to implement group-based segmentation. Endpoints are assigned SGTs, and Security Group ACLs (SGACLs) enforce policy between groups. This approach provides micro-segmentation without the need for traditional VRFs on every switch, simplifying operations and improving security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Access Control List (ACL)
Why it's wrong here
ACLs are static and applied per interface or globally. They do not provide the dynamic, group-based policy model of SD-Access. Managing ACLs across a large fabric for many departments is operationally complex and does not meet the requirement for scalable segmentation.
- ✓
Scalable Group Tag (SGT)
Why this is correct
SGTs are used in Cisco SD-Access to provide micro-segmentation. Each endpoint is assigned an SGT, and group-based policies (SGACLs) enforce traffic between groups. This allows segmentation without traditional VRFs on every switch, meeting the requirement for secure departmental separation.
- ✗
VLAN pool
Why it's wrong here
VLAN pools are used in SD-Access to allocate VLANs to fabric-enabled switches, but they do not provide security segmentation between departments. They are a mechanism for VLAN assignment, not for enforcing group-based policies. VLANs alone do not offer the granular, identity-based segmentation required.
- ✗
Virtual Routing and Forwarding (VRF)
Why it's wrong here
VRFs provide Layer 3 segmentation but require configuration on every device and do not scale as dynamically as SGT-based policies. The scenario explicitly asks for segmentation without traditional VRFs on every switch, so VRF is not the correct solution here.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.