Courseiva
Architecture →hardMultiple Select

CCNP Architecture Practice Question

A network engineer is deploying Cisco SD-WAN in a hybrid cloud environment. The company requires secure segmentation between guest, employee, and IoT traffic across all branches. The engineer must ensure that traffic from each segment is isolated and that policies can be applied per segment. Which two components are used to achieve this segmentation? (Choose two.)

⚠ Common exam trap

Many candidates confuse segmentation mechanisms with transport security or local VLANs, which do not provide end-to-end isolation across the SD-WAN fabric.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN segments in vManage

In Cisco SD-WAN, segmentation is achieved by creating VPN segments in vManage and mapping them to VRF instances on the WAN Edge devices. The VPN segments define the logical separation, and the VRFs enforce it by maintaining separate routing and forwarding tables. Together, they provide end-to-end isolation and allow policies to be applied per segment. Other options like VLANs or IPsec tunnels do not provide fabric-wide segmentation, and application-aware routing policies are for path selection, not isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VPN segments in vManage

    Why this is correct

    VPN segments in vManage allow the creation of separate virtual private networks (VPNs) within the SD-WAN overlay. Each segment has its own routing table and can be assigned to different VRFs on the WAN Edge devices. This provides isolation between guest, employee, and IoT traffic. Policies can be applied per VPN segment, enabling granular control. This is a core mechanism for segmentation in Cisco SD-WAN.

  • ✗

    Application-aware routing policies

    Why it's wrong here

    Application-aware routing policies control path selection based on application performance, but they do not provide traffic segmentation. They are used to steer traffic based on SLA, not to isolate segments. While they can be applied per VPN, they are not the component that creates the segmentation itself. The question asks for components used to achieve segmentation, not policy enforcement.

  • ✓

    VRF instances on WAN Edge devices

    Why this is correct

    VRF instances on WAN Edge devices are used to instantiate VPN segments. Each VPN segment maps to a VRF, which maintains a separate routing table and forwarding instance. This ensures that traffic from different segments is isolated. The VRF is the actual implementation of the segmentation on the device, working in conjunction with vManage to distribute the configuration. This is a correct component for achieving segmentation.

  • ✗

    IPsec tunnels between branches

    Why it's wrong here

    IPsec tunnels provide secure transport between branches, but they do not inherently provide segmentation. All segments can share the same IPsec tunnels, with segmentation enforced via VPN segments and VRFs. IPsec ensures confidentiality and integrity, but without VPN segmentation, traffic from different segments would mix. Therefore, IPsec tunnels alone do not achieve the required isolation.

  • ✗

    VLANs on the WAN Edge routers

    Why it's wrong here

    VLANs on WAN Edge routers are used for local LAN segmentation, but they do not provide end-to-end segmentation across the SD-WAN fabric. VLANs are Layer 2 constructs and are not carried across the overlay. While they can map to VPN segments, they alone do not achieve the required isolation and policy enforcement across all branches. They are a local mechanism, not a fabric-wide segmentation solution.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.