mediumMultiple Choice
CCNP Practice Question: A network architect is designing a Cisco…
A network architect is designing a Cisco SD-Access fabric for a university campus that requires segmentation between student, faculty, and guest traffic. The design must use Cisco TrustSec for scalable security group tags (SGTs) and integrate with Cisco ISE for policy enforcement. Which fabric component should the architect use to enforce SGT-based policies at the access layer?
⚠ Common exam trap
Cisco often tests the misconception that the fabric border node or control plane node enforces policies, when in fact the fabric edge node is the only device that applies SGT-based access control at the access layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fabric edge node
The fabric edge node is the correct component because it is the access-layer switch in Cisco SD-Access that performs SGT-based enforcement. It receives SGT-to-SGT policy from Cisco ISE via the control plane node and applies the corresponding security ACLs (SGACLs) at the port level, ensuring segmentation between student, faculty, and guest traffic at the point of entry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fabric border node
Why it's wrong here
The fabric border node's role is to connect the SD-Access fabric to external networks (e.g., WAN, data center, non- fabric sites) and perform LISP-to-BGP/EGP translation and VRF normalization. Although it can handle SGTs for inter-fabric traffic and may be involved in SGT propagation, it is not the device that enforces SGT policies at the access layer. The access layer is owned by the fabric edge switch, which is the first-hop device for endpoint traffic and the only place where SGACL enforcement can be applied to locally attached hosts. The border node simply forwards traffic beyond the fabric, without acting as the enforcement point for endpoint-to-endpoint SGT policies.
- ✗
Fabric control plane node
Why it's wrong here
The fabric control plane node is responsible for maintaining the LISP EID-to-RLOC mapping database and processing map-request/map-reply messages, ensuring that endpoints are routable across the fabric. It is completely out of the data forwarding path, meaning it never sees actual user packets, so it cannot apply SGACL checks or any SGT-based traffic filtering. Even if it holds policy definitions or SGT mapping information, enforcement requires inline hardware inspection that only the fabric edge switch can perform at the access layer. Hence, the control plane node is a routing intelligence service, not a policy enforcement point.
- ✓
Fabric edge node
Why this is correct
The fabric edge switch is the correct enforcement point for SGT policies in an SD-Access fabric. When a wired or wireless endpoint authenticates via ISE, the edge switch receives the SGT through RADIUS (or CoA) and associates it with the endpoint's MAC/IP address. Every packet from that endpoint is then classified with the SGT, and the edge switch applies the corresponding SGACL in hardware to permit or deny traffic based on source and destination SGTs. This occurs at the access layer, exactly where the endpoint connects, making the fabric edge the critical device for enforcing SGT-based policies.
- ✗
Wireless LAN controller
Why it's wrong here
Although the WLC can integrate with ISE to authenticate wireless clients and may receive SGT attributes for those sessions, it does not enforce SGT policies itself. In Cisco SD-Access, wireless traffic is tunneled from the access point to the fabric edge switch, which terminates the client's traffic and acts as the first-hop fabric device. The WLC essentially passes authentication and SGT information to the fabric edge via CAPWAP, and the edge switch performs the actual SGACL enforcement for wireless users. Therefore, the WLC is not an enforcement point at the access layer; it only contributes to identity and policy signaling, leaving the enforcement to the fabric edge node.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.