Courseiva
Architecture →mediumMultiple Select

CCNP Architecture Practice Question

A network architect is designing a Cisco SD-WAN fabric using vManage, vSmart, and vBond controllers. Which two statements accurately describe the control plane and onboarding behavior in this architecture? (Choose two.)

⚠ Common exam trap

The trap here is mixing management-plane and control-plane roles, such as assuming vManage forwards data or that OSPF runs in the overlay instead of OMP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The vBond controller authenticates and orchestrates initial connectivity between WAN Edge devices and the controllers.

In Cisco SD-WAN, vBond handles authentication and orchestration of initial control connections, while vSmart is the control plane that uses OMP to distribute routing and policy information. vManage is management plane only, OSPF is not the overlay routing protocol, and vBond generally needs public reachability for discovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vBond controller must be deployed behind a NAT device and cannot have a public IP address.

    Why it's wrong here

    vBond typically requires a publicly reachable address so that WAN Edge devices can contact it from anywhere. While NAT traversal options exist for edge devices, requiring vBond to be behind NAT and without a public IP is not accurate. This would hinder initial onboarding and controller discovery.

  • ✗

    WAN Edge devices must run OSPF in the overlay to exchange routes with each other.

    Why it's wrong here

    WAN Edge devices do not run OSPF across the overlay to exchange routes. They use OMP with vSmart for overlay reachability. OSPF may be used on the service side or in the underlay, but the overlay control plane is OMP-based, so requiring OSPF in the overlay is incorrect for SD-WAN.

  • ✓

    The vBond controller authenticates and orchestrates initial connectivity between WAN Edge devices and the controllers.

    Why this is correct

    This is correct because vBond is the first point of contact for WAN Edge devices; it validates their identity and provides the information needed to reach vManage and vSmart. It acts as the orchestrator for control connections, enabling secure onboarding without pre-configuring every peer address on each edge device.

  • ✗

    The vManage controller forwards user data traffic between WAN Edge devices in the data plane.

    Why it's wrong here

    vManage is the management plane component that provides GUI, API, and configuration management. It does not forward user data traffic; data-plane forwarding occurs directly between WAN Edge devices over IPsec tunnels. Claiming that vManage carries user traffic misstates its role and would create an unnecessary bottleneck.

  • ✓

    The vSmart controller distributes control-plane policies and routes overlay topology information to WAN Edge devices via OMP.

    Why this is correct

    This is correct because vSmart is the centralized control plane. It uses the Overlay Management Protocol to exchange reachability, TLOC, and policy information with WAN Edge devices. This allows the fabric to make forwarding decisions based on centralized policy rather than running a traditional routing protocol across the overlay.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.