CCNP Virtualization Practice Question
A network engineer is deploying a Cisco SD-Access fabric. The design requires that endpoints be authenticated and assigned to a VLAN and VRF based on their identity before any traffic is forwarded. Which Cisco SD-Access component is responsible for this function?
⚠ Common exam trap
The trap here is assuming the fabric edge node or control plane node performs endpoint authentication and VLAN/VRF assignment, when that is actually the role of Cisco ISE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco Identity Services Engine
Cisco ISE is the identity services component that authenticates endpoints and returns the VLAN and VRF assignment to the fabric edge node. The edge node then places the endpoint into the correct virtual network and applies group-based policy. Neither the control plane nor border nodes perform authentication or endpoint classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco Identity Services Engine
Why this is correct
Cisco ISE authenticates endpoints using 802.1X, MAC authentication bypass, or web authentication, and returns the VLAN and VRF (or SGT) assignment to the fabric edge node. This is the identity services function that enforces policy before forwarding.
- ✗
Fabric border node
Why it's wrong here
The border node provides connectivity between the SD-Access fabric and external networks, such as the data center or WAN. It handles VXLAN-to-VLAN or VRF-lite handoff and does not authenticate endpoints or assign them to VLANs or VRFs.
- ✗
Fabric control plane node
Why it's wrong here
The control plane node maintains the endpoint-to-edge-node mapping in the LISP map-server and map-resolver. It answers location queries but does not authenticate endpoints or decide which VLAN or VRF they belong to; that assignment is made by the identity services engine.
- ✗
Fabric edge node
Why it's wrong here
The fabric edge node encapsulates VXLAN traffic and enforces policy, but it relies on the control plane and identity services to determine the endpoint's group. It does not independently perform authentication or assign VLAN/VRF; it receives that mapping from the fabric control plane and identity services.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.