hardMultiple Select
CCNP Practice Question: Which three statements about SD-WAN segmentation…
Which three statements about SD-WAN segmentation and multi-tenancy are true? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Each VPN in SD-WAN corresponds to a separate VRF on the edge device, providing Layer 3 isolation.
Option A is correct because in Cisco SD-WAN each VPN is mapped to a distinct VRF on the edge device, which provides Layer 3 routing isolation between segments. Option B is correct because OMP carries VPN membership in its routing updates, so edge devices learn which VPNs are reachable through each TLOC. Option C is correct because extranet VPN configuration enables controlled route sharing between different VPNs on the same edge device, allowing selective inter-VPN connectivity. Option D is incorrect because VPN 0 is the transport VPN used for WAN/control connections, not service-side LAN or data center connectivity. Option E is incorrect because SD-WAN multi-tenancy can be achieved logically through VPN segmentation on shared edge devices, without requiring separate physical devices per tenant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Each VPN in SD-WAN corresponds to a separate VRF on the edge device, providing Layer 3 isolation.
Why this is correct
Each SD-WAN VPN maps to a distinct VRF on the edge device, so routes and forwarding tables remain separate between segments. This satisfies the multi-tenancy requirement for Layer 3 isolation, preventing traffic leaking between tenants or departments.
- ✓
OMP advertises VPN membership information so that edge devices know which VPNs are reachable via each TLOC.
Why this is correct
OMP carries VPN membership in its TLOC routes, so each edge learns which VPNs sit behind every TLOC. This reachability data lets the edge forward traffic only to TLOCs participating in the required VPN, satisfying the segmentation requirement.
- ✓
Extranet VPN configuration allows selected routes to be shared between different VPNs on the same edge device.
Why this is correct
Extranet VPNs permit controlled route leaking between otherwise isolated VRFs on one edge device, satisfying the requirement to share selected routes across tenants without full isolation. Each VPN retains its own forwarding table; only explicitly exported prefixes cross the boundary, which is precisely the multi-tenancy segmentation behaviour the stem asks about.
- ✗
VPN 0 is used for service-side connectivity, such as connecting to a corporate LAN or data center.
Why it's wrong here
VPN 0 is the transport VPN carrying WAN uplinks and control connections; service-side connectivity such as corporate LAN or data centre attachment uses VPN 1 (or another service VPN). Confusing the two is tempting because VPN 0 does carry traffic, but it is reserved for transport, not service-side interfaces.
- ✗
Multi-tenancy in SD-WAN requires separate physical edge devices for each tenant to ensure isolation.
Why it's wrong here
SD-WAN multi-tenancy isolates tenants logically through VPN segmentation (VRF-like separation) on shared edge devices, so dedicated hardware per tenant is not required. Separate physical edges are tempting where regulatory or security mandates demand full hardware isolation, but that is a design choice, not a multi-tenancy requirement.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.