Courseiva
mediumMultiple Select

CCNP Practice Question: Which two statements about the Cisco SD-Access…

Which two statements about the Cisco SD-Access fabric roles are true? (Choose two.)

⚠ Common exam trap

350-401 often tests the specific functions of each fabric role, and candidates may confuse intermediate nodes with edge nodes or think the WLC is a border node.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The fabric edge node is responsible for connecting end devices and enforcing SGT-based policies.

Option A is correct because the fabric edge node is the device (typically a Catalyst switch) that connects wired endpoints into the SD-Access fabric, registers them with the control plane, and enforces group-based policies using SGTs (Security Group Tags) via SGACL and CTS. Option B is correct because the fabric border node provides the handoff between the SD-Access fabric and external Layer 3 networks (such as the data center, WAN, or Internet), performing VRF-aware route leaking and SGT propagation across the fabric boundary. Option C is incorrect because the control plane node (running LISP map-server/map-resolver) handles endpoint registration and location mapping, not user traffic encapsulation; that is the role of edge and border nodes using VXLAN. Option D is incorrect because intermediate nodes simply forward VXLAN-encapsulated traffic between fabric edge and border nodes based on the underlay routing, and they do not perform policy enforcement or segmentation. Option E is incorrect because in SD-Access the wireless controller (WLC) integrates with the fabric as a fabric-enabled WLC (or is replaced by embedded wireless on Catalyst 9800), not as a dedicated fabric border node for wireless traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The fabric edge node is responsible for connecting end devices and enforcing SGT-based policies.

    Why this is correct

    Fabric edge nodes sit at the fabric boundary, connecting wired and wireless endpoints into the VXLAN overlay and applying group-based policy via SGT enforcement at the ingress point, satisfying the stem's requirement for both endpoint attachment and policy enforcement.

  • ✓

    The fabric border node is responsible for connecting the SD-Access fabric to external Layer 3 networks.

    Why this is correct

    The fabric border node provides the handoff between the SD-Access fabric's VXLAN domain and external Layer 3 networks, peering with devices outside the fabric. This external connectivity role is what distinguishes it from edge and control plane nodes.

  • ✗

    The control plane node is responsible for encapsulating and forwarding user traffic across the fabric.

    Why it's wrong here

    Encapsulation and forwarding of user traffic is the fabric edge node's role via VXLAN, not the control plane node's. The control plane node runs LISP for host tracking and mapping. It is tempting because control plane functions sound traffic-related, but that is the data plane.

  • ✗

    The intermediate node is responsible for policy enforcement and traffic segmentation within the fabric.

    Why it's wrong here

    Policy enforcement and segmentation are handled by the fabric edge node applying group-based policies via SGTs, not the intermediate node. Intermediate nodes only forward VXLAN traffic between edge and border. It is tempting because intermediate nodes sit in the path, but they perform no policy function.

  • ✗

    The wireless controller in SD-Access acts as a dedicated fabric border node for wireless traffic.

    Why it's wrong here

    In SD-Access the wireless controller integrates as a fabric-enabled device, with access points registering to fabric edge nodes, not acting as a dedicated border. It is tempting because wireless traffic must exit the fabric somewhere, but that egress uses the standard border node, not the controller.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.