Courseiva
Architecture →mediumMultiple Choice

350-401 Architecture Practice Question

A network architect is designing a new branch office that must support wired and wireless users with a single unified policy and automated onboarding for guests. The design requires centralized management, fabric-based segmentation, and the ability to enforce group-based policies without manual VLAN provisioning at the branch. Which Cisco architecture should be used?

⚠ Common exam trap

The trap here is assuming that Catalyst Center automation alone delivers fabric segmentation, when SD-Access specifically provides the fabric overlay and group-based policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco SD-Access

Cisco SD-Access is the campus fabric solution that integrates wired and wireless into a single policy domain using LISP, VXLAN, and TrustSec. It centralizes management through Cisco DNA Center and enables automated onboarding and group-based segmentation without manual VLAN configuration, making it the correct architecture for the branch requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cisco ACI

    Why it's wrong here

    Cisco ACI is designed for data center networks with a spine-leaf topology and policy model based on endpoint groups. It does not natively manage branch campus access switches or wireless onboarding, and its fabric constructs are not intended for distributed branch LAN segmentation with wireless integration.

  • ✓

    Cisco SD-Access

    Why this is correct

    Cisco SD-Access is a campus fabric architecture that uses LISP for control plane, VXLAN for data plane, and Cisco TrustSec for group-based policy. It provides centralized management via Cisco DNA Center, automated fabric provisioning, and consistent policy for wired and wireless users, including guest onboarding, which matches the requirements exactly.

  • ✗

    Cisco SD-WAN

    Why it's wrong here

    Cisco SD-WAN focuses on WAN transport overlays, dynamic path selection, and policy for inter-site traffic, but it does not provide campus fabric segmentation or group-based policy enforcement for wired and wireless users at a branch. It cannot replace the access-layer fabric functions needed for automated onboarding and microsegmentation within the branch LAN.

  • ✗

    Cisco Catalyst Center with traditional VLANs

    Why it's wrong here

    Cisco Catalyst Center can automate VLAN and device configuration, but a traditional VLAN-based design still requires manual VLAN provisioning and does not provide fabric-based segmentation or group-based policy enforcement. It lacks the integrated control plane and data plane encapsulation that SD-Access uses for scalable policy.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.