350-401 Security Practice Question
A network architect is designing a Cisco SD-Access fabric. The security team requires that endpoint traffic be segmented into separate virtual networks and that group-based policy be enforced without using traditional VLANs or ACLs between fabric edge nodes. Which two Cisco SD-Access fabric components or features support these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming that legacy Layer 2 isolation tools such as private VLANs or extended ACLs can deliver fabric-wide segmentation and group policy in SD-Access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric
SD-Access uses VXLAN encapsulation with a fabric VNI per virtual network to provide data-plane segmentation, and it carries Security Group Tags so that group-based policy can be enforced consistently across fabric edge nodes. Together these deliver segmentation and policy without depending on VLANs or hop-by-hop ACLs between edge switches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric
Why this is correct
SGTs carry group-based policy information in the VXLAN header, allowing the fabric to enforce scalable group-based access control across edge nodes without hop-by-hop ACLs. This satisfies the requirement for group-based policy enforcement that is independent of VLAN or IP subnet boundaries in the SD-Access fabric.
- ✓
Virtual Extensible LAN (VXLAN) data plane encapsulation with fabric VNIs
Why this is correct
VXLAN with fabric VNIs provides the data-plane segmentation in SD-Access, mapping each virtual network to a unique VNI so endpoints in different VNs are isolated even when sharing the same underlay. This replaces traditional VLAN-based segmentation at the fabric edge, matching the requirement for separate virtual networks without relying on VLANs between edge nodes.
- ✗
Private VLANs configured on every fabric edge switch port
Why it's wrong here
Private VLANs operate at Layer 2 within a single switch or VLAN domain and do not scale or propagate across an SD-Access fabric. They cannot provide segmentation across fabric edge nodes, and SD-Access does not use them as the isolation mechanism, so they fail to meet the design requirement.
- ✗
Dynamic ARP Inspection on all fabric underlay links
Why it's wrong here
Dynamic ARP Inspection validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing. It is a Layer 2 security feature and does not provide virtual network segmentation or group-based policy, so it does not address the stated SD-Access design goals.
- ✗
Extended ACLs applied inbound on every fabric edge uplink
Why it's wrong here
Extended ACLs are traditional hop-by-hop filters that become operationally complex and do not scale to fabric-wide group policy. The requirement explicitly excludes ACL-based enforcement between edge nodes, and ACLs do not create separate virtual networks, so they are unsuitable here.
Visual reference
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.