Courseiva
Infrastructure →hardMultiple Select

CCNP Infrastructure Practice Question

A network engineer is deploying a new Cisco SD-WAN fabric using Cisco vManage, vSmart, and vBond controllers. The engineer must ensure that the control plane is secure and resilient. Which two statements are true regarding the roles of these controllers? (Choose two.)

⚠ Common exam trap

The trap here is conflating the roles of vBond and vSmart; vBond handles authentication and orchestration, while vSmart handles control plane policies and routing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vSmart distributes control plane policies and routing information to WAN edge devices using OMP.

In Cisco SD-WAN, vBond orchestrates the control plane by authenticating and validating controllers and WAN edge devices, facilitating NAT traversal. vSmart distributes control plane policies and routing information using OMP. vManage is the management plane for configuration and monitoring. These roles are distinct and critical for a secure and resilient fabric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vSmart distributes control plane policies and routing information to WAN edge devices using OMP.

    Why this is correct

    vSmart is the control plane controller that uses the Overlay Management Protocol (OMP) to distribute routing, policy, and security information to WAN edge devices. It maintains a centralized view of the overlay and ensures consistent policy enforcement. It does not handle device authentication; that is vBond's role. vSmart is essential for dynamic path selection and policy application across the SD-WAN fabric.

  • ✗

    vBond maintains the routing table and makes path selection decisions for the overlay.

    Why it's wrong here

    vBond does not maintain routing tables or make path selection decisions. Its role is limited to orchestration and authentication. Routing and path selection are handled by vSmart, which uses OMP to distribute reachability and policy information. WAN edge devices then make forwarding decisions based on that information. vBond only facilitates the initial control plane connections, not ongoing routing.

  • ✓

    vBond orchestrates the control plane and is responsible for authenticating and validating all other controllers and WAN edge devices.

    Why this is correct

    vBond acts as the orchestrator, authenticating and validating vSmart, vManage, and WAN edge devices when they join the overlay. It facilitates NAT traversal and provides the initial handshake, ensuring only authorized devices participate. It does not maintain routing information or policies; those are handled by vSmart and vManage. This makes vBond critical for secure onboarding and resilience of the control plane.

  • ✗

    vSmart is responsible for the initial device authentication and NAT traversal.

    Why it's wrong here

    Initial device authentication and NAT traversal are functions of vBond, not vSmart. vBond authenticates devices and helps them establish connections through NAT. vSmart then handles control plane policies and routing. Mistaking vSmart for vBond is a common error, but their roles are distinct. vSmart does not perform authentication or NAT traversal; it focuses on OMP and policy distribution.

  • ✗

    vManage is responsible for authenticating WAN edge devices and distributing encryption keys.

    Why it's wrong here

    vManage is the management plane, providing a GUI and API for configuration, monitoring, and troubleshooting. It does not authenticate devices or distribute encryption keys. Authentication and key distribution are handled by vBond and vSmart, respectively. vManage may push configuration templates, but it relies on the control plane for secure operations. Confusing vManage's role with vBond's is a common mistake.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.