CCNP Architecture Practice Question
A network engineer is deploying Cisco SD-WAN in a hybrid cloud environment. The company requires secure segmentation between guest, employee, and IoT traffic across all branches. The engineer must ensure that traffic from each segment is isolated and that policies can be applied per segment. Which two components are used to achieve this segmentation? (Choose two.)
⚠ Common exam trap
Many candidates confuse segmentation mechanisms with transport security or local VLANs, which do not provide end-to-end isolation across the SD-WAN fabric.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPN segments in vManage
In Cisco SD-WAN, segmentation is achieved by creating VPN segments in vManage and mapping them to VRF instances on the WAN Edge devices. The VPN segments define the logical separation, and the VRFs enforce it by maintaining separate routing and forwarding tables. Together, they provide end-to-end isolation and allow policies to be applied per segment. Other options like VLANs or IPsec tunnels do not provide fabric-wide segmentation, and application-aware routing policies are for path selection, not isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VPN segments in vManage
Why this is correct
VPN segments in vManage allow the creation of separate virtual private networks (VPNs) within the SD-WAN overlay. Each segment has its own routing table and can be assigned to different VRFs on the WAN Edge devices. This provides isolation between guest, employee, and IoT traffic. Policies can be applied per VPN segment, enabling granular control. This is a core mechanism for segmentation in Cisco SD-WAN.
- ✗
Application-aware routing policies
Why it's wrong here
Application-aware routing policies control path selection based on application performance, but they do not provide traffic segmentation. They are used to steer traffic based on SLA, not to isolate segments. While they can be applied per VPN, they are not the component that creates the segmentation itself. The question asks for components used to achieve segmentation, not policy enforcement.
- ✓
VRF instances on WAN Edge devices
Why this is correct
VRF instances on WAN Edge devices are used to instantiate VPN segments. Each VPN segment maps to a VRF, which maintains a separate routing table and forwarding instance. This ensures that traffic from different segments is isolated. The VRF is the actual implementation of the segmentation on the device, working in conjunction with vManage to distribute the configuration. This is a correct component for achieving segmentation.
- ✗
IPsec tunnels between branches
Why it's wrong here
IPsec tunnels provide secure transport between branches, but they do not inherently provide segmentation. All segments can share the same IPsec tunnels, with segmentation enforced via VPN segments and VRFs. IPsec ensures confidentiality and integrity, but without VPN segmentation, traffic from different segments would mix. Therefore, IPsec tunnels alone do not achieve the required isolation.
- ✗
VLANs on the WAN Edge routers
Why it's wrong here
VLANs on WAN Edge routers are used for local LAN segmentation, but they do not provide end-to-end segmentation across the SD-WAN fabric. VLANs are Layer 2 constructs and are not carried across the overlay. While they can map to VPN segments, they alone do not achieve the required isolation and policy enforcement across all branches. They are a local mechanism, not a fabric-wide segmentation solution.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.