hardMultiple Choice
CCNP Practice Question: Deploying an SD-Access fabric with a centralized…
A company is deploying an SD-Access fabric with a centralized policy model. The design must ensure that all traffic between virtual networks (VNs) is inspected by a firewall. Which fabric role should be used to enforce this inter-VN policy?
⚠ Common exam trap
Cisco often tests the misconception that fabric edge nodes enforce all policies, but the trap here is that inter-VN traffic requires a routing point (the border node) to apply firewall inspection, while edge nodes only enforce intra-VN policies like SGT-based access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fabric border node
In a centralized policy model for SD-Access, the fabric border node is the correct role to enforce inter-VN traffic policies because it is the only node that can route traffic between different virtual networks (VNs) while applying firewall inspection. The border node connects the fabric to external networks and, when configured with a firewall, can enforce policies such as IP-based ACLs or zone-based firewalls for traffic crossing VNs. This design ensures that all inter-VN traffic is funneled through the border node for inspection, aligning with the centralized policy model where policy enforcement occurs at the network edge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Fabric border node
Why this is correct
The fabric border node is the correct answer because it serves as the gateway between the SD-Access fabric and external networks (such as a data center or WAN). Critically, border nodes can apply policy-based routing (PBR) to inter-VN traffic, allowing it to be steered to an external firewall for inspection before being allowed to continue — a capability that makes the border node the natural point for inter-VN policy enforcement. In Cisco SD-Access, border nodes also perform LISP proxy-ETR (PETR) and proxy-ITR functionality, enabling them to handle traffic destined outside the fabric and to apply security policy at the network edge without needing a dedicated internal firewall. Thus, the border node is specifically designed to enforce inter-VN security policy, not just forward traffic.
- ✗
Fabric edge node
Why it's wrong here
A fabric edge node is incorrect because its primary role is to connect end hosts to the fabric and to enforce intra-VN policies (e.g., VN segmentation and SGT-based ACLs) for traffic within the same virtual network. Edge nodes do not perform inter-VN policy-based routing by default; inter-VN traffic is typically sent to the border node for any required inspection or policy enforcement. While edge nodes can apply SGT-based access policies, they are not architected for inter-VN inspection scenarios where traffic must be redirected to a firewall — that redirection and inspection is a border-node function. Therefore, selecting the fabric edge node would mischaracterize the SD-Access design role for inter-VN traffic forwarding.
- ✗
Fabric control plane node
Why it's wrong here
A fabric control plane node is incorrect because it is a logical function (often co-located with a border node) that provides the LISP map server and map resolver services, maintaining the EID-to-RLOC mappings for all fabric devices. Control plane nodes do not participate in the data plane; they receive map-register and map-request messages but do not forward user data traffic. Since they do not forward traffic, they cannot enforce or apply packet-inspection policies like firewall redirection for inter-VN traffic. The control plane's role is purely signaling and mapping, so it is not the correct answer for a node that steers traffic to a firewall.
- ✗
Fabric WAN router
Why it's wrong here
A fabric WAN router is incorrect because its function is to provide connectivity from the SD-Access fabric to external wide-area networks (e.g., MPLS, Internet, or VPNs) at the network edge. While a WAN router can have routing policies, it is not the SD-Access component specifically designated for inter-VN policy enforcement; that role belongs to the fabric border node. In a typical SD-Access design, the WAN router connects to the border node (or is integrated into it) and does not natively participate in LISP or VXLAN forwarding within the fabric. Even if a WAN router could apply ACLs or PBR, it is not the architecturally correct point for steering inter-VN traffic to a firewall, whereas the border node has explicit LISP routing and policy-injection capabilities for that purpose.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.