CCNP Security Practice Question
A network architect is designing a Cisco SD-Access fabric. The security team requires that endpoint traffic be segmented into separate virtual networks and that group-based policy be enforced without using traditional VLANs or ACLs between fabric edge nodes. Which two Cisco SD-Access fabric components or features support these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming that legacy Layer 2 isolation tools such as private VLANs or extended ACLs can deliver fabric-wide segmentation and group policy in SD-Access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric
SD-Access uses VXLAN encapsulation with a fabric VNI per virtual network to provide data-plane segmentation, and it carries Security Group Tags so that group-based policy can be enforced consistently across fabric edge nodes. Together these deliver segmentation and policy without depending on VLANs or hop-by-hop ACLs between edge switches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric
Why this is correct
SGTs carry group-based policy information in the VXLAN header, allowing the fabric to enforce scalable group-based access control across edge nodes without hop-by-hop ACLs. This satisfies the requirement for group-based policy enforcement that is independent of VLAN or IP subnet boundaries in the SD-Access fabric.
- ✓
Virtual Extensible LAN (VXLAN) data plane encapsulation with fabric VNIs
Why this is correct
VXLAN with fabric VNIs provides the data-plane segmentation in SD-Access, mapping each virtual network to a unique VNI so endpoints in different VNs are isolated even when sharing the same underlay. This replaces traditional VLAN-based segmentation at the fabric edge, matching the requirement for separate virtual networks without relying on VLANs between edge nodes.
- ✗
Private VLANs configured on every fabric edge switch port
Why it's wrong here
Private VLANs operate at Layer 2 within a single switch or VLAN domain and do not scale or propagate across an SD-Access fabric. They cannot provide segmentation across fabric edge nodes, and SD-Access does not use them as the isolation mechanism, so they fail to meet the design requirement.
- ✗
Dynamic ARP Inspection on all fabric underlay links
Why it's wrong here
Dynamic ARP Inspection validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing. It is a Layer 2 security feature and does not provide virtual network segmentation or group-based policy, so it does not address the stated SD-Access design goals.
- ✗
Extended ACLs applied inbound on every fabric edge uplink
Why it's wrong here
Extended ACLs are traditional hop-by-hop filters that become operationally complex and do not scale to fabric-wide group policy. The requirement explicitly excludes ACL-based enforcement between edge nodes, and ACLs do not create separate virtual networks, so they are unsuitable here.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.