Courseiva
Virtualization →mediumMultiple Choice

CCNP Virtualization Practice Question

A network engineer is deploying a new branch office that uses Cisco SD-WAN with a single transport underlay. The design requires that the branch router participate in the SD-WAN fabric and establish control connections to the controllers. Which component must the engineer configure on the branch device to allow it to register with the SD-WAN controllers and receive policy from vManage?

⚠ Common exam trap

The trap here is assuming that an underlay routing protocol such as BGP or OSPF with the controllers is required for registration, when in fact the SD-WAN control plane uses TLS/DTLS tunnels authenticated by organization name and system IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A unique system IP address and organization name configured on the device

For a Cisco SD-WAN device to join the overlay, it must be configured with a unique system IP address and the same organization name as the controllers. These values are used during the initial vBond handshake and subsequent control connections to vSmart and vManage. Without them, the device cannot authenticate, receive centralized policy, or participate in the fabric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A unique system IP address and organization name configured on the device

    Why this is correct

    The system IP and organization name are the two identifiers the SD-WAN controllers use to authenticate and track a device. Without a matching organization name and a unique system IP, the device cannot establish control connections to vBond, vSmart, and vManage, so it will not receive centralized policy or join the overlay.

  • ✗

    An IPsec pre-shared key matching the vBond controller

    Why it's wrong here

    Authentication in SD-WAN is based on the organization name and device certificates or, in some deployments, a one-time bootstrap. A pre-shared key matching vBond is not the mechanism used for a branch device to register and receive policy. Configuring only an IPsec key would leave the device unable to authenticate to the controllers.

  • ✗

    A VRF named TRANSPORT with an OSPF process advertising the system IP

    Why it's wrong here

    While a transport VRF may be used in some designs, OSPF advertising the system IP is not what enables controller registration. The device joins the fabric through control connections to vBond, vManage, and vSmart, authenticated by organization name and system IP. OSPF is an underlay routing choice, not the registration method.

  • ✗

    A BGP autonomous system number peering with the vSmart controller

    Why it's wrong here

    SD-WAN control connections use DTLS/TLS tunnels to the controllers, not a BGP session with vSmart. While OMP runs inside the fabric, the branch device does not peer BGP with vSmart to register. A BGP ASN alone will not allow the device to join the SD-WAN overlay or obtain policy.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.