Courseiva
Architecture →hardMultiple Choice

CCNP Architecture Practice Question

A network engineer is implementing Cisco SD-Access and needs to ensure that endpoints in a virtual network can communicate with a shared service that resides in a different virtual network. The shared service must be reachable from multiple virtual networks without duplicating the service. Which SD-Access component should be configured to provide this inter-VN communication?

⚠ Common exam trap

Test-takers frequently confuse the border node's role of external connectivity with the fusion router's role of inter-VN routing and shared services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fusion router

The fusion router is specifically designed to enable inter-VN communication and shared services in Cisco SD-Access. It connects to the fabric border node and uses VRF leaking to allow endpoints in different virtual networks to reach common services. Fabric edge nodes, border nodes, and control plane nodes have different roles and do not provide this function. The fusion router ensures that shared services are not duplicated across VNs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Control plane node

    Why it's wrong here

    Control plane nodes in SD-Access run the LISP map-server and map-resolver functions, providing endpoint location mapping. They do not route traffic between virtual networks or provide access to shared services. They are essential for fabric operation but do not perform inter-VN routing or shared service reachability.

  • ✓

    Fusion router

    Why this is correct

    The fusion router is used in SD-Access to provide inter-VN routing and to connect to shared services that reside outside the fabric or in a different VN. It allows multiple virtual networks to reach a common service without duplicating it. It is typically connected to the border node and runs VRF-aware routing to leak routes between VNs.

  • ✗

    Fabric edge node

    Why it's wrong here

    Fabric edge nodes connect wired endpoints to the SD-Access fabric and encapsulate traffic in VXLAN. They enforce group-based policies but do not provide inter-VN routing or shared services. They can only route within the same virtual network or to the fusion router if configured, but they do not natively allow a shared service to be reached from multiple VNs without additional configuration.

  • ✗

    Fabric border node

    Why it's wrong here

    Fabric border nodes connect the SD-Access fabric to external networks (e.g., WAN, data center) and handle VXLAN-to-VLAN or VXLAN-to-VXLAN handoff. They do not provide inter-VN routing between virtual networks within the fabric. While they can connect to a fusion router, they are not the component that enables shared services across VNs.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.