Courseiva
Architecture →hardMultiple Select

350-401 Architecture Practice Question

A network architect is evaluating Cisco SD-Access for a large campus. The architect must ensure the fabric supports policy enforcement based on user identity and group membership, and that the fabric can scale to thousands of endpoints without flooding the underlay. Which two statements are correct about how SD-Access achieves these goals? (Choose two.)

⚠ Common exam trap

The trap here is assuming the SD-Access underlay floods endpoint information or carries host routes, when endpoint reachability is actually resolved by LISP in the overlay.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The LISP control plane in SD-Access registers endpoint EID-to-RLOC mappings so fabric edge nodes can resolve destinations without flooding the underlay.

SD-Access scales by moving endpoint reachability into the LISP control plane, where EID-to-RLOC mappings are registered and resolved, avoiding underlay flooding. Policy is enforced with Cisco TrustSec group tags carried in the VXLAN Group Policy Option header, enabling group-based ACLs at fabric edge nodes. The underlay is a routed IS-IS fabric that does not carry endpoint host routes or rely on VXLAN flooding, and the overlay does not require a single stretched bridge domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The fabric uses a single shared bridge domain across all edge nodes to avoid VLAN proliferation.

    Why it's wrong here

    SD-Access can use a shared subnet for a virtual network, but it does not rely on a single shared Layer 2 bridge domain stretched across all edge nodes. Stretching one bridge domain would reintroduce flooding and scale problems. Instead, the overlay uses LISP and VXLAN so endpoints in the same virtual network appear local without a stretched Layer 2 domain.

  • ✗

    The underlay uses VXLAN flooding to propagate endpoint reachability to all fabric edge nodes.

    Why it's wrong here

    The SD-Access underlay is a routed Layer 3 fabric, typically using IS-IS, and does not use VXLAN flooding to propagate endpoint reachability. VXLAN is used in the overlay, and reachability is learned through the LISP control plane, not through flooding. Relying on flooding would not scale to thousands of endpoints as the scenario requires.

  • ✓

    The LISP control plane in SD-Access registers endpoint EID-to-RLOC mappings so fabric edge nodes can resolve destinations without flooding the underlay.

    Why this is correct

    In SD-Access, the LISP map server and map resolver track endpoint identifier to routing locator mappings. Fabric edge nodes register local endpoints and query the map server for remote ones, which provides a control-plane lookup instead of data-plane flooding. This is how the fabric scales to thousands of endpoints while avoiding broadcast or unknown unicast flooding across the underlay.

  • ✓

    Cisco TrustSec security group tags are carried in the VXLAN Group Policy Option header so fabric edge nodes can enforce group-based ACLs.

    Why this is correct

    SD-Access uses Cisco TrustSec to assign security group tags to endpoints. These tags are carried inside the VXLAN Group Policy Option header, allowing fabric edge nodes to enforce scalable group-based ACLs without relying on IP-based rules. This provides identity and group-based policy enforcement across the fabric, which is a core requirement in the scenario.

  • ✗

    Fabric edge nodes use OSPF to advertise endpoint host routes into the underlay for reachability.

    Why it's wrong here

    The SD-Access underlay carries only infrastructure reachability, such as loopbacks and fabric-enabled link networks, using IS-IS. Endpoint host routes are not advertised into the underlay with OSPF. Endpoint reachability is handled in the overlay by LISP, so this statement misrepresents how the fabric scales and how endpoints are resolved.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.