CCNP Architecture Practice Question
A network architect is designing a new branch office that requires a lightweight, scalable solution for device onboarding and policy enforcement. The branch has minimal on-site IT staff and must integrate with the existing Cisco DNA Center deployment at headquarters. Which Cisco SD-Access fabric role is responsible for providing the layer 3 gateway and policy enforcement for wired and wireless endpoints in this branch?
⚠ Common exam trap
The trap here is assuming that any fabric node can enforce policy and act as a gateway, when in fact only the edge node performs those functions for endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fabric edge node
The fabric edge node is the device that connects endpoints to the SD-Access fabric and serves as their default gateway. It enforces group-based policies and encapsulates traffic in VXLAN toward other fabric nodes. In a branch with limited IT staff, it enables zero-touch onboarding and centralized policy from Cisco DNA Center, satisfying both scalability and integration needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fabric border node
Why it's wrong here
The border node connects the SD-Access fabric to external networks such as the WAN or data center. It handles VXLAN-to-VLAN or VXLAN-to-VXLAN handoff and may host fusion routers. It does not act as the layer 3 gateway for fabric endpoints, so it does not meet the stated requirement.
- ✗
Fabric control plane node
Why it's wrong here
The control plane node maintains endpoint location information using LISP and responds to map requests. It does not provide layer 3 gateway services or enforce policy for endpoints. While essential for scalability, it does not fulfill the gateway and policy enforcement role described in the scenario.
- ✗
Fabric intermediate node
Why it's wrong here
Intermediate nodes are underlay devices that provide IP transport between fabric nodes. They do not participate in VXLAN encapsulation or endpoint registration. They simply forward fabric traffic based on the underlay routing protocol, so they cannot provide gateway or policy enforcement services for endpoints.
- ✓
Fabric edge node
Why this is correct
The fabric edge node provides the layer 3 gateway and policy enforcement for endpoints in the SD-Access fabric. It encapsulates traffic using VXLAN and registers endpoints with the control plane node. In a branch with minimal IT staff, the edge node enables automated onboarding and consistent policy from Cisco DNA Center, exactly as required.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.