Courseiva
Network Fundamentals →hardMultiple Select

200-901 Network Fundamentals Practice Question

Which THREE of the following are benefits of using an SDN (Software-Defined Networking) architecture compared to traditional networking? (Choose three.)

⚠ Common exam trap

Cisco often tests the misconception that SDN eliminates the need for network engineers entirely, but the correct understanding is that SDN automates tasks and centralizes control, not that it removes the human role in network design and troubleshooting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation of network configuration changes.

Option B is correct because SDN's centralized controller exposes northbound APIs (e.g., REST) that let orchestration tools push configuration programmatically, enabling automation of network configuration changes instead of manual CLI work on each device. Option C is correct because that same programmable control plane allows new services and policies to be provisioned in software via the controller rather than waiting on per-device hardware configuration, so new network services deploy faster. Option D is correct because SDN logically centralizes the control plane in a controller, giving a single, network-wide view and centralized control and visibility over all data-plane devices. Option A is not a benefit—SDN changes the skill set required but does not inherently reduce the need for network engineers. Option E is not a benefit—SDN does not provide built-in encryption for all traffic; encryption is handled by separate mechanisms such as IPsec, TLS, or MACsec.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduced need for network engineers.

    Why it's wrong here

    SDN centralises control-plane policy, which shifts engineering effort toward automation and programmability rather than eliminating staff. Reduced headcount is tempting because automation removes repetitive CLI configuration, but the architecture's documented benefit is consistent policy deployment, not workforce reduction.

  • ✓

    Automation of network configuration changes.

    Why this is correct

    SDN separates the control plane from the data plane, letting a controller push configuration programmatically via APIs. This replaces per-device CLI changes, so network configuration changes are automated across the fabric rather than performed manually, satisfying the benefit of reduced manual effort and human error.

  • ✓

    Faster deployment of new network services.

    Why this is correct

    Because the SDN controller provisions paths and policies through software rather than waiting on manual device-by-device configuration, new network services can be instantiated in minutes. This directly satisfies the faster deployment benefit by removing the sequential hardware-by-hardware provisioning bottleneck of traditional networking.

  • ✓

    Centralized control and visibility of the network.

    Why this is correct

    SDN's controller maintains a global view of the entire network and enforces policy from one point, unlike traditional networking where each device holds only local state. This satisfies the centralized control and visibility benefit, giving administrators a single pane for topology, flows and policy.

  • ✗

    Built-in encryption for all network traffic.

    Why it's wrong here

    SDN separates the control plane from the data plane; it does not encrypt packets, which remains the job of IPsec, MACsec or TLS. Encryption is tempting because centralised controllers ease policy distribution, but confidentiality is a separate security function, not an inherent SDN property.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.