CCNP Virtualization Practice Question
A network architect is designing a Cisco SD-Access fabric. The requirement is to provide Layer 3 isolation between different departments while allowing them to share the same physical network. Which Cisco SD-Access component is responsible for providing this isolation?
⚠ Common exam trap
Candidates often confuse the data plane identifier (VNI) with the logical isolation construct (VN). While a VNI is used to separate traffic in the encapsulation, the actual Layer 3 isolation is provided by the VN's associated VRF.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Virtual Network (VN)
In Cisco SD-Access, Layer 3 isolation between departments is achieved by assigning them to different Virtual Networks (VNs). Each VN is essentially a separate VRF, and the fabric uses VXLAN with distinct VNIs to carry traffic for each VN. This allows the same physical infrastructure to support multiple isolated logical networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Locator/ID Separation Protocol (LISP)
Why it's wrong here
LISP is the control plane protocol used in SD-Access for endpoint location and mapping. It does not provide Layer 3 isolation. LISP enables the fabric to route based on endpoint identifiers, but isolation is achieved through VNs and their associated VRFs.
- ✗
Scalable Group Tag (SGT)
Why it's wrong here
SGTs are used for group-based policy and micro-segmentation within a VN, not for creating Layer 3 isolation between departments. While SGTs can enforce policy, they do not provide the VRF-like separation that a VN does. The scenario explicitly requires Layer 3 isolation, which is a VN function.
- ✓
Virtual Network (VN)
Why this is correct
In Cisco SD-Access, a Virtual Network (VN) is a logical partition that provides Layer 3 isolation. Each VN is associated with a VRF, and endpoints in different VNs cannot communicate at Layer 3 unless there is a fusion router or external policy. This meets the requirement for department isolation while sharing the physical underlay.
- ✗
VXLAN Network Identifier (VNI)
Why it's wrong here
A VNI is used in VXLAN encapsulation to identify the Layer 2 or Layer 3 segment. In SD-Access, each VN is mapped to a VNI, but the VNI itself is just an identifier. The isolation is provided by the VN, which is the logical construct that encompasses the VNI and the associated VRF.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.