Courseiva
Virtualization →mediumMultiple Choice

CCNP Virtualization Practice Question

A network engineer is deploying a Cisco SD-Access fabric using Cisco DNA Center. The design requires that endpoints in the same virtual network (VN) be able to communicate even when they are attached to different fabric edge nodes. Which data plane technology does SD-Access use to carry the endpoint traffic across the fabric underlay?

⚠ Common exam trap

Test-takers frequently confuse the SD-Access data plane with other tunneling technologies like GRE or MPLS, which are not used inside the SD-Access fabric.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VXLAN with a fabric VNI mapped to each virtual network

Cisco SD-Access uses VXLAN as the data plane encapsulation. Each virtual network is mapped to a unique VNI, and the fabric edge and border nodes encapsulate endpoint traffic in VXLAN. This allows endpoints in the same VN to communicate across different edge nodes while preserving segmentation. The control plane uses LISP to map endpoint identities to fabric locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MPLS L3VPN with a route target per virtual network

    Why it's wrong here

    MPLS L3VPN is a service provider technology that uses VRFs and route targets to separate customer traffic. It is not used inside a Cisco SD-Access fabric. SD-Access uses VXLAN with a LISP-based control plane. While MPLS can provide segmentation, it does not match the SD-Access architecture or the requirement for endpoint mobility and fabric encapsulation.

  • ✗

    GRE with a tunnel key per virtual network

    Why it's wrong here

    GRE is a generic tunneling protocol and can carry overlay traffic, but it is not the data plane encapsulation used by Cisco SD-Access. SD-Access specifically uses VXLAN because it provides a 24-bit VNI space and is supported in hardware on the fabric switches. GRE would not provide the required scale or integration with the SD-Access control plane based on LISP.

  • ✗

    OTV with an overlay VLAN per virtual network

    Why it's wrong here

    OTV is a Cisco technology for extending Layer 2 between data centers over a Layer 3 transport. It is not the encapsulation used in SD-Access. OTV uses its own adjacency and doesn't provide the VNI-based segmentation or the control plane integration that SD-Access requires. Using OTV would not meet the fabric requirements for endpoint communication across edge nodes.

  • ✓

    VXLAN with a fabric VNI mapped to each virtual network

    Why this is correct

    SD-Access uses VXLAN encapsulation in the fabric data plane. Each virtual network is mapped to a unique VNI, and the fabric edge nodes and border nodes act as VTEPs. The endpoint traffic is carried inside VXLAN tunnels across the underlay, which allows Layer 2 and Layer 3 communication between endpoints attached to different edge nodes while maintaining segmentation.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.