mediumMultiple Choice
CCNP Practice Question: An architect is designing an SD-Access fabric for…
An architect is designing an SD-Access fabric for a campus network that must support dynamic endpoint grouping based on user identity and device type. The design must minimize manual policy configuration and allow the fabric to enforce access policies at the edge. Which combination of components and protocols is required to meet these requirements?
⚠ Common exam trap
Cisco often tests the specific roles of LISP (control plane) and VXLAN (data plane) in SD-Access, and the trap here is confusing their functions or assuming that traditional protocols like OSPF/BGP or ACLs/VLANs can replace the overlay control and policy enforcement mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco ISE for policy management, LISP for control plane, VXLAN for data plane, and Cisco TrustSec for SGT-based enforcement
SD-Access uses Cisco ISE as the policy engine to define user/device-based policies, LISP as the control plane for endpoint-to-location mapping and mobility, VXLAN as the data plane for overlay encapsulation, and Cisco TrustSec for SGT-based enforcement at the edge. This combination enables dynamic endpoint grouping without manual ACLs, as SGTs are propagated via VXLAN Group Policy Option (GPO) and enforced by the fabric edge switches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco ISE for policy management, LISP for control plane, VXLAN for data plane, and Cisco TrustSec for SGT-based enforcement
Why this is correct
In Cisco SD-Access, ISE authenticates users and assigns Scalable Group Tags (SGTs) to define policy; LISP serves as the overlay control plane, decoupling routing from endpoint location to support host mobility and scale. VXLAN is the data plane encapsulation that transparently carries traffic and embeds the SGT in its header for group-based enforcement at fabric edge nodes. TrustSec uses those SGTs rather than IP addresses to enforce security policies consistently across the fabric, which is exactly the intended role of each protocol in the architecture.
- ✗
Cisco ISE for policy management, OSPF for control plane, GRE for data plane, and ACLs for enforcement
Why it's wrong here
OSPF is an underlay IGP that only builds the IP routing table between fabric devices; it cannot act as a control plane for overlay endpoint discovery or host tracking, which LISP performs in SD-Access. GRE tunnels are simple stateless encapsulations that lack VXLAN's scalability, multicast support, and ability to carry SGT information in the outer header, so they are unsuitable for fabric data plane. ACLs enforce policy based on static IP addresses or subnets, not on dynamically assigned SGTs, so this combination would not provide the identity-based, group-aware enforcement SD-Access requires. Thus, while OSPF and GRE could exist in an underlay, they are not the fabric overlay protocols.
- ✗
Cisco ISE for policy management, BGP for control plane, MPLS for data plane, and VLANs for enforcement
Why it's wrong here
BGP is not used as the SD-Access control plane; LISP is required for endpoint-to-location mapping and host mobility, while BGP is more appropriate for WAN routing or EVPN in other environments. MPLS is a WAN transport technology that relies on label switching and does not provide the Ethernet encapsulation or VXLAN header extension needed to carry SGTs and segment traffic in a campus fabric. VLANs only partition broadcast domains at Layer 2 and do not enforce SGT-based security policies, so they cannot replace TrustSec enforcement. In short, this stack confuses campus fabric requirements with service-provider MPLS VPN principles and lacks the overlay and group-based policy capabilities of SD-Access.
- ✗
Cisco ISE for policy management, LISP for data plane, VXLAN for control plane, and 802.1X for enforcement
Why it's wrong here
This option reverses the roles of the two overlay protocols: LISP is the control plane that resolves endpoint IDs to routing locators (RLOC) to locate hosts, whereas VXLAN is the data plane encapsulation that carries packets across the fabric between VTEPs. 802.1X performs port-based network access control during the authentication phase, but it does not apply per-packet security policies after a session is established; that enforcement is done by TrustSec using SGTs. Swapping LISP and VXLAN would leave no protocol to encapsulate data and no mechanism to track endpoint locations, making the fabric nonfunctional. Therefore the protocol functions are mismatched and would not support SD-Access operations.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.