Courseiva
Architecture →hardMultiple Choice

CCNP Architecture Practice Question

A network engineer is designing a Cisco SD-Access fabric for a campus network. The fabric must support both wired and wireless clients, and the engineer wants to ensure that traffic from wired endpoints is encapsulated and forwarded through the fabric without requiring the endpoints to change their IP addresses. Which component of the SD-Access architecture is responsible for encapsulating traffic from wired endpoints and forwarding it to the fabric edge?

⚠ Common exam trap

Watch out — candidates often confuse the role of the fabric edge node with that of the border node, assuming that any fabric device can encapsulate endpoint traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fabric edge node

In Cisco SD-Access, the fabric edge node is the device that connects wired endpoints to the fabric. It encapsulates traffic from wired endpoints into VXLAN and forwards it to the destination fabric edge node based on the control plane mapping. This allows endpoints to keep their IP addresses and be part of a virtual network without re-addressing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Control plane node

    Why it's wrong here

    The control plane node maintains the mapping of endpoint identities to fabric edge nodes using LISP. It does not encapsulate or forward data traffic from wired endpoints. Its role is to provide the control plane database for endpoint location, not to perform VXLAN encapsulation of user traffic.

  • ✓

    Fabric edge node

    Why this is correct

    The fabric edge node is responsible for encapsulating traffic from wired endpoints using VXLAN and forwarding it to the fabric. It acts as the first-hop router for endpoints and registers them with the control plane node. This component is essential for wired client integration in SD-Access, as it provides the anycast gateway and encapsulation functions.

  • ✗

    Fabric intermediate node

    Why it's wrong here

    The fabric intermediate node is a Layer 3 underlay device that forwards VXLAN-encapsulated traffic between fabric edge and border nodes. It does not encapsulate traffic from wired endpoints; it only transports the encapsulated packets based on the outer IP header. It has no knowledge of endpoint identities or fabric encapsulation functions.

  • ✗

    Fabric border node

    Why it's wrong here

    The fabric border node connects the SD-Access fabric to external networks such as the data center or WAN. It does not encapsulate traffic from wired endpoints; instead, it handles traffic entering or leaving the fabric. While it may de-encapsulate VXLAN traffic for external destinations, it is not the first point of encapsulation for wired endpoints.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.