350-401 Architecture Practice Question
A network architect is designing a Cisco SD-WAN fabric for a company with 50 branch sites. The company requires that each branch have two WAN transports (MPLS and Internet) with per-application traffic steering, and that the fabric use a controller-based architecture for centralized policy. Which Cisco SD-WAN component is responsible for distributing fabric-wide policy and managing control plane connectivity?
⚠ Common exam trap
Many exam-takers confuse the management plane role of vManage with the control plane policy distribution role of vSmart.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vSmart controller
In Cisco SD-WAN, the vSmart controller is the brain of the control plane. It distributes OMP routes and policies to all vEdge routers, enabling centralized policy and per-application traffic steering. The vBond orchestrator handles initial authentication, vManage provides management, and vEdge routers forward data. Only vSmart distributes fabric-wide policy and manages control plane connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vManage NMS
Why it's wrong here
vManage is the network management system used for configuration, monitoring, and troubleshooting via GUI. It can push policy templates, but the actual distribution of control plane routes and enforcement of policy to vEdge routers is done by another controller. It is not responsible for the control plane connectivity or OMP route distribution.
- ✓
vSmart controller
Why this is correct
The vSmart controller is the centralized policy and control plane component of Cisco SD-WAN. It distributes OMP routes and policies to vEdge routers, enabling per-application traffic steering across MPLS and Internet transports. It does not forward data traffic; it only manages control plane and policy. This matches the requirement for centralized policy in a controller-based architecture.
- ✗
vEdge router
Why it's wrong here
vEdge routers are the data plane devices at branch sites that forward traffic and enforce policy locally. They receive policy from the controller but do not distribute it to other devices. They also do not manage control plane connectivity for the entire fabric; that is the role of a centralized controller.
- ✗
vBond orchestrator
Why it's wrong here
vBond orchestrator handles initial authentication and orchestration of vEdge devices, including NAT traversal and validating device certificates. It does not distribute fabric-wide policy or manage ongoing control plane routes. While essential for onboarding, it is not the component that enforces per-application traffic steering policies across the fabric.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.