Courseiva
Security →mediumMultiple Select

350-401 Security Practice Question

A network architect is designing a Cisco SD-Access fabric. The security team requires that endpoint traffic be segmented into separate virtual networks and that group-based policy be enforced without using traditional VLANs or ACLs between fabric edge nodes. Which two Cisco SD-Access fabric components or features support these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that legacy Layer 2 isolation tools such as private VLANs or extended ACLs can deliver fabric-wide segmentation and group policy in SD-Access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric

SD-Access uses VXLAN encapsulation with a fabric VNI per virtual network to provide data-plane segmentation, and it carries Security Group Tags so that group-based policy can be enforced consistently across fabric edge nodes. Together these deliver segmentation and policy without depending on VLANs or hop-by-hop ACLs between edge switches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric

    Why this is correct

    SGTs carry group-based policy information in the VXLAN header, allowing the fabric to enforce scalable group-based access control across edge nodes without hop-by-hop ACLs. This satisfies the requirement for group-based policy enforcement that is independent of VLAN or IP subnet boundaries in the SD-Access fabric.

  • ✓

    Virtual Extensible LAN (VXLAN) data plane encapsulation with fabric VNIs

    Why this is correct

    VXLAN with fabric VNIs provides the data-plane segmentation in SD-Access, mapping each virtual network to a unique VNI so endpoints in different VNs are isolated even when sharing the same underlay. This replaces traditional VLAN-based segmentation at the fabric edge, matching the requirement for separate virtual networks without relying on VLANs between edge nodes.

  • ✗

    Private VLANs configured on every fabric edge switch port

    Why it's wrong here

    Private VLANs operate at Layer 2 within a single switch or VLAN domain and do not scale or propagate across an SD-Access fabric. They cannot provide segmentation across fabric edge nodes, and SD-Access does not use them as the isolation mechanism, so they fail to meet the design requirement.

  • ✗

    Dynamic ARP Inspection on all fabric underlay links

    Why it's wrong here

    Dynamic ARP Inspection validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing. It is a Layer 2 security feature and does not provide virtual network segmentation or group-based policy, so it does not address the stated SD-Access design goals.

  • ✗

    Extended ACLs applied inbound on every fabric edge uplink

    Why it's wrong here

    Extended ACLs are traditional hop-by-hop filters that become operationally complex and do not scale to fabric-wide group policy. The requirement explicitly excludes ACL-based enforcement between edge nodes, and ACLs do not create separate virtual networks, so they are unsuitable here.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.