Courseiva
Virtualization →hardMultiple Choice

350-401 Virtualization Practice Question

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide secure segmentation for different departments without deploying separate physical networks or traditional VRFs on every switch. Which Cisco SD-Access component provides this segmentation by using a group-based policy model?

⚠ Common exam trap

The trap here is assuming that VRFs are the only way to segment traffic, overlooking the identity-based, group-policy model that SD-Access provides through SGTs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scalable Group Tag (SGT)

Cisco SD-Access uses Scalable Group Tags (SGTs) to implement group-based segmentation. Endpoints are assigned SGTs, and Security Group ACLs (SGACLs) enforce policy between groups. This approach provides micro-segmentation without the need for traditional VRFs on every switch, simplifying operations and improving security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Access Control List (ACL)

    Why it's wrong here

    ACLs are static and applied per interface or globally. They do not provide the dynamic, group-based policy model of SD-Access. Managing ACLs across a large fabric for many departments is operationally complex and does not meet the requirement for scalable segmentation.

  • ✓

    Scalable Group Tag (SGT)

    Why this is correct

    SGTs are used in Cisco SD-Access to provide micro-segmentation. Each endpoint is assigned an SGT, and group-based policies (SGACLs) enforce traffic between groups. This allows segmentation without traditional VRFs on every switch, meeting the requirement for secure departmental separation.

  • ✗

    VLAN pool

    Why it's wrong here

    VLAN pools are used in SD-Access to allocate VLANs to fabric-enabled switches, but they do not provide security segmentation between departments. They are a mechanism for VLAN assignment, not for enforcing group-based policies. VLANs alone do not offer the granular, identity-based segmentation required.

  • ✗

    Virtual Routing and Forwarding (VRF)

    Why it's wrong here

    VRFs provide Layer 3 segmentation but require configuration on every device and do not scale as dynamically as SGT-based policies. The scenario explicitly asks for segmentation without traditional VRFs on every switch, so VRF is not the correct solution here.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.