Courseiva
mediumMultiple Choice

CCNP Practice Question: Is designing a WAN connection for a branch office…

A network engineer is designing a WAN connection for a branch office that requires high availability and bandwidth aggregation. The branch has two internet connections from different ISPs. The engineer wants to use both links actively for load balancing and failover. Which design approach should be used?

⚠ Common exam trap

Cisco often tests the misconception that BGP multipath or static routes with HSRP can achieve active/active load balancing, but these methods either require complex tuning or are inherently active/passive, failing to meet the policy-based and application-aware requirements that SD-WAN uniquely addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy SD-WAN to actively use both links with policy-based load balancing.

SD-WAN is the correct design because it natively supports active/active utilization of multiple WAN links with policy-based load balancing, allowing traffic to be distributed across both ISP connections based on application policies, SLA metrics, or other criteria. It also provides seamless failover by dynamically rerouting traffic if one link fails, meeting the requirements for high availability and bandwidth aggregation without relying on a single active link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy SD-WAN to actively use both links with policy-based load balancing.

    Why this is correct

    SD-WAN is purpose-built for active/active WAN utilization: it establishes secure overlay tunnels across both transport links and uses centralized or distributed policy-based routing to steer traffic per application, class, or SLA. This allows both links to carry production traffic simultaneously, with dynamic path selection for load balancing and fast reroute if one link degrades or fails. The policy engine also factors in real-time loss, latency, and jitter, making it the only option that truly satisfies the requirement to actively use both links.

  • ✗

    Configure static routes with different metrics for each link and use HSRP for failover.

    Why it's wrong here

    Configuring static routes with different metrics creates an active/passive WAN topology: traffic always prefers the lower-metric link, and only on failure does the higher-metric route take over. This yields failover, not load balancing, and does not actively utilize both links in steady state. HSRP operates at Layer 2/3 for default gateway redundancy within the LAN, not for WAN path selection; it has no mechanism to split or balance traffic across two upstream ISP links.

  • ✗

    Use BGP with both ISPs and rely on BGP best path selection for load balancing.

    Why it's wrong here

    BGP by default installs only the single best path to a destination, regardless of how many eBGP peers are receiving the same prefix, so it would select one ISP link for a given route. Even with BGP multipath and maximum-paths configured, path selection is based on BGP attributes such as local preference and AS path, not on current link utilization or application requirements; all traffic to a prefix still follows the chosen path(s) in a coarse manner. BGP is a reachability and policy protocol, not an active load-sharing mechanism, and per-packet or per-application balancing requires additional configuration that goes far beyond 'just using BGP'.

  • ✗

    Implement a VPN tunnel between the branch and headquarters using only one link.

    Why it's wrong here

    This approach tunnels traffic over a single physical link, so the second ISP link remains unused for all branch-to-headquarters traffic. Such a design provides no bandwidth aggregation and no active/active load balancing; if the selected link fails, the VPN tunnel itself goes down and the branch loses connectivity unless a backup tunnel on the other link is preconfigured. Even with a backup tunnel, operations are still active/passive, which does not meet the stated requirement to actively use both links.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.