350-401 Architecture Practice Question
A network architect is designing a new branch office that must support wired and wireless users with a single unified policy and automated onboarding for guests. The design requires centralized management, fabric-based segmentation, and the ability to enforce group-based policies without manual VLAN provisioning at the branch. Which Cisco architecture should be used?
⚠ Common exam trap
The trap here is assuming that Catalyst Center automation alone delivers fabric segmentation, when SD-Access specifically provides the fabric overlay and group-based policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco SD-Access
Cisco SD-Access is the campus fabric solution that integrates wired and wireless into a single policy domain using LISP, VXLAN, and TrustSec. It centralizes management through Cisco DNA Center and enables automated onboarding and group-based segmentation without manual VLAN configuration, making it the correct architecture for the branch requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cisco ACI
Why it's wrong here
Cisco ACI is designed for data center networks with a spine-leaf topology and policy model based on endpoint groups. It does not natively manage branch campus access switches or wireless onboarding, and its fabric constructs are not intended for distributed branch LAN segmentation with wireless integration.
- ✓
Cisco SD-Access
Why this is correct
Cisco SD-Access is a campus fabric architecture that uses LISP for control plane, VXLAN for data plane, and Cisco TrustSec for group-based policy. It provides centralized management via Cisco DNA Center, automated fabric provisioning, and consistent policy for wired and wireless users, including guest onboarding, which matches the requirements exactly.
- ✗
Cisco SD-WAN
Why it's wrong here
Cisco SD-WAN focuses on WAN transport overlays, dynamic path selection, and policy for inter-site traffic, but it does not provide campus fabric segmentation or group-based policy enforcement for wired and wireless users at a branch. It cannot replace the access-layer fabric functions needed for automated onboarding and microsegmentation within the branch LAN.
- ✗
Cisco Catalyst Center with traditional VLANs
Why it's wrong here
Cisco Catalyst Center can automate VLAN and device configuration, but a traditional VLAN-based design still requires manual VLAN provisioning and does not provide fabric-based segmentation or group-based policy enforcement. It lacks the integrated control plane and data plane encapsulation that SD-Access uses for scalable policy.
Visual reference
Go deeper
Related to this question
Learn chapter
Wireless Fundamentals and 802.11 Standards
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
Key term
Cisco Virtual Topology System
Cisco Virtual Topology System is a software-defined networking solution that creates and manages virtual network overlays across physical and virtual infrastructure for enterprise networks.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.