CCNP Architecture Practice Question
A network engineer is implementing Cisco SD-Access and needs to ensure that the fabric provides policy-based segmentation and mobility for endpoints. Which component is responsible for maintaining the endpoint location and identity information?
⚠ Common exam trap
Many exam-takers confuse the management plane (DNA Center) or policy plane (ISE) with the control plane (LISP Map-Server) that actually tracks endpoint location and identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LISP Map-Server
The LISP Map-Server is responsible for maintaining endpoint location and identity information in Cisco SD-Access. It registers EID-to-RLOC mappings from fabric edge nodes and provides them to other nodes upon request. This enables seamless mobility and policy-based segmentation, as endpoints can be reached regardless of their physical location. Other components like DNA Center and ISE play different roles in management and policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cisco Identity Services Engine (ISE)
Why it's wrong here
Cisco ISE provides authentication, authorization, and accounting (AAA) services and can assign security group tags (SGTs) based on identity. However, it does not maintain endpoint location information; that is handled by the LISP Map-Server. ISE integrates with SD-Access for policy enforcement but is not the component that tracks endpoint location. Thus, it is not the correct answer.
- ✓
LISP Map-Server
Why this is correct
The LISP Map-Server maintains the mapping of endpoint identities (EIDs) to routing locators (RLOCs), effectively tracking endpoint location and identity. It registers EID-to-RLOC mappings from fabric edge nodes and responds to map requests. This enables policy-based segmentation and mobility by allowing endpoints to be reached regardless of their location. Thus, it is the correct component.
- ✗
Cisco DNA Center
Why it's wrong here
Cisco DNA Center is the management platform for SD-Access, providing automation, assurance, and policy definition. It does not maintain real-time endpoint location and identity; that function is handled by the LISP control plane. DNA Center pushes policies and configurations but relies on other components for endpoint tracking. Therefore, it is not the correct answer.
- ✗
VXLAN Tunnel Endpoint (VTEP)
Why it's wrong here
A VTEP is responsible for encapsulating and decapsulating VXLAN traffic. It does not maintain endpoint location and identity information; that is the role of the LISP control plane. VTEPs forward data based on mappings provided by LISP. In SD-Access, fabric edge nodes act as VTEPs, but they query the Map-Server for endpoint locations. Therefore, this is not the correct answer.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.