200-901 Network Fundamentals Practice Question
Which THREE of the following are benefits of using an SDN (Software-Defined Networking) architecture compared to traditional networking? (Choose three.)
⚠ Common exam trap
Cisco often tests the misconception that SDN eliminates the need for network engineers entirely, but the correct understanding is that SDN automates tasks and centralizes control, not that it removes the human role in network design and troubleshooting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation of network configuration changes.
Option B is correct because SDN's centralized controller exposes northbound APIs (e.g., REST) that let orchestration tools push configuration programmatically, enabling automation of network configuration changes instead of manual CLI work on each device. Option C is correct because that same programmable control plane allows new services and policies to be provisioned in software via the controller rather than waiting on per-device hardware configuration, so new network services deploy faster. Option D is correct because SDN logically centralizes the control plane in a controller, giving a single, network-wide view and centralized control and visibility over all data-plane devices. Option A is not a benefit—SDN changes the skill set required but does not inherently reduce the need for network engineers. Option E is not a benefit—SDN does not provide built-in encryption for all traffic; encryption is handled by separate mechanisms such as IPsec, TLS, or MACsec.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduced need for network engineers.
Why it's wrong here
SDN centralises control-plane policy, which shifts engineering effort toward automation and programmability rather than eliminating staff. Reduced headcount is tempting because automation removes repetitive CLI configuration, but the architecture's documented benefit is consistent policy deployment, not workforce reduction.
- ✓
Automation of network configuration changes.
Why this is correct
SDN separates the control plane from the data plane, letting a controller push configuration programmatically via APIs. This replaces per-device CLI changes, so network configuration changes are automated across the fabric rather than performed manually, satisfying the benefit of reduced manual effort and human error.
- ✓
Faster deployment of new network services.
Why this is correct
Because the SDN controller provisions paths and policies through software rather than waiting on manual device-by-device configuration, new network services can be instantiated in minutes. This directly satisfies the faster deployment benefit by removing the sequential hardware-by-hardware provisioning bottleneck of traditional networking.
- ✓
Centralized control and visibility of the network.
Why this is correct
SDN's controller maintains a global view of the entire network and enforces policy from one point, unlike traditional networking where each device holds only local state. This satisfies the centralized control and visibility benefit, giving administrators a single pane for topology, flows and policy.
- ✗
Built-in encryption for all network traffic.
Why it's wrong here
SDN separates the control plane from the data plane; it does not encrypt packets, which remains the job of IPsec, MACsec or TLS. Encryption is tempting because centralised controllers ease policy distribution, but confidentiality is a separate security function, not an inherent SDN property.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.