mediumMultiple Choice
CCNP Practice Question: A network architect is designing the QoS…
A network architect is designing the QoS architecture for a Cisco SD-WAN deployment that carries voice, video, and data traffic across MPLS and Internet transports. The design must use a consistent DiffServ marking strategy across all transports and ensure that voice traffic is prioritized over video. Which QoS policy type and marking approach should the architect use?
⚠ Common exam trap
Cisco often tests the misconception that localized QoS policies are sufficient for multi-transport consistency, but the trap here is that only centralized QoS policies in SD-WAN can enforce uniform DiffServ markings across all transports, while options like NBAR2 or per-transport markings (EXP vs. IP Precedence) fail to meet the requirement for a consistent strategy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a centralized QoS policy that marks traffic with DSCP and applies per-queue shaping on the WAN edge.
Cisco SD-WAN uses centralized QoS policies applied via vSmart to ensure consistent DiffServ marking (DSCP) across all transports (MPLS and Internet). Per-queue shaping on the WAN edge router allows voice traffic to be prioritized over video by assigning voice to a higher-priority queue (e.g., queue 4 with DSCP EF) and video to a lower queue (e.g., queue 3 with DSCP AF41), ensuring voice is always serviced first.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use localized QoS policies on each WAN edge router with CoS markings based on the transport type.
Why it's wrong here
Per-device localized QoS policies configured directly on each WAN edge router create a management and operational split from the SD-WAN controller. Because the markings are based on the transport type, the same application could receive different CoS (802.1p) values on MPLS versus Internet links, breaking any consistent end-to-end quality strategy. Moreover, Layer 2 CoS bits are not preserved through IPsec tunnels or across the provider network, so they are a poor choice for an IP-based SD-WAN fabric. Centralized policy is required to ensure uniform classification and queue treatment across all sites and transports.
- ✓
Use a centralized QoS policy that marks traffic with DSCP and applies per-queue shaping on the WAN edge.
Why this is correct
A centralized QoS policy, defined in vManage and pushed to all WAN edge routers, is the correct SD-WAN approach because it applies identical DSCP marking rules regardless of the underlying transport. DSCP operates at the IP layer, so it can be preserved across IPsec tunnels by instructing the tunnel to copy the outer TOS field, allowing service providers and remote routers to honor priority markings. The per-queue shaping component uses scheduling constructs such as strict priority for voice and a separate bandwidth pool for video, ensuring that real-time traffic receives predictable latency and jitter even when a transport link is congested. This transport-independent, centrally managed model is the foundation of Cisco SD-WAN QoS.
- ✗
Use MPLS EXP markings for MPLS transport and IP Precedence for Internet transport.
Why it's wrong here
Using MPLS EXP bits on the MPLS transport and IP Precedence on the Internet transport forces the SD-WAN policy to depend on the transport medium rather than the application, which defeats the purpose of a unified QoS strategy. MPLS EXP is a Layer 2.5 shim header that is typically overwritten or re-marked by the provider's ingress router, while IP Precedence has only 8 values, far less granular than the 64 DSCP classes available for application classification. Since the same traffic would be marked differently on each transport, forwarding decisions and per-hop behaviors would be inconsistent, causing voice or video to be treated differently depending on the selected circuit. This fragmentation makes troubleshooting and SLA enforcement extremely difficult and does not align with centralized SD-WAN policy design.
- ✗
Use NBAR2 to automatically classify traffic and apply markings based on application signatures.
Why it's wrong here
NBAR2 is a local classification mechanism that inspects application signatures on the device itself, but it does not provide a centralized, fabric-wide QoS policy in the SD-WAN architecture. Running NBAR2 per router would require independent configuration and tuning on every edge device, and the classification outcome (the assigned markings) would still need to be tied to a local policy, which can drift between devices and lacks vManage’s centralized enforcement and monitoring. Additionally, NBAR2 performance impact and the difficulty of guaranteeing identical application signatures across different software versions make it unsuitable as the primary QoS policy mechanism. In SD-WAN, centralized policy is applied from the controller; NBAR2 could be used as an optional local classification tool, but not as the sole source of QoS marking.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.