350-401 Architecture Practice Question
A network architect is evaluating Cisco SD-Access for a large campus. The architect must ensure the fabric supports policy enforcement based on user identity and group membership, and that the fabric can scale to thousands of endpoints without flooding the underlay. Which two statements are correct about how SD-Access achieves these goals? (Choose two.)
⚠ Common exam trap
The trap here is assuming the SD-Access underlay floods endpoint information or carries host routes, when endpoint reachability is actually resolved by LISP in the overlay.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The LISP control plane in SD-Access registers endpoint EID-to-RLOC mappings so fabric edge nodes can resolve destinations without flooding the underlay.
SD-Access scales by moving endpoint reachability into the LISP control plane, where EID-to-RLOC mappings are registered and resolved, avoiding underlay flooding. Policy is enforced with Cisco TrustSec group tags carried in the VXLAN Group Policy Option header, enabling group-based ACLs at fabric edge nodes. The underlay is a routed IS-IS fabric that does not carry endpoint host routes or rely on VXLAN flooding, and the overlay does not require a single stretched bridge domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The fabric uses a single shared bridge domain across all edge nodes to avoid VLAN proliferation.
Why it's wrong here
SD-Access can use a shared subnet for a virtual network, but it does not rely on a single shared Layer 2 bridge domain stretched across all edge nodes. Stretching one bridge domain would reintroduce flooding and scale problems. Instead, the overlay uses LISP and VXLAN so endpoints in the same virtual network appear local without a stretched Layer 2 domain.
- ✗
The underlay uses VXLAN flooding to propagate endpoint reachability to all fabric edge nodes.
Why it's wrong here
The SD-Access underlay is a routed Layer 3 fabric, typically using IS-IS, and does not use VXLAN flooding to propagate endpoint reachability. VXLAN is used in the overlay, and reachability is learned through the LISP control plane, not through flooding. Relying on flooding would not scale to thousands of endpoints as the scenario requires.
- ✓
The LISP control plane in SD-Access registers endpoint EID-to-RLOC mappings so fabric edge nodes can resolve destinations without flooding the underlay.
Why this is correct
In SD-Access, the LISP map server and map resolver track endpoint identifier to routing locator mappings. Fabric edge nodes register local endpoints and query the map server for remote ones, which provides a control-plane lookup instead of data-plane flooding. This is how the fabric scales to thousands of endpoints while avoiding broadcast or unknown unicast flooding across the underlay.
- ✓
Cisco TrustSec security group tags are carried in the VXLAN Group Policy Option header so fabric edge nodes can enforce group-based ACLs.
Why this is correct
SD-Access uses Cisco TrustSec to assign security group tags to endpoints. These tags are carried inside the VXLAN Group Policy Option header, allowing fabric edge nodes to enforce scalable group-based ACLs without relying on IP-based rules. This provides identity and group-based policy enforcement across the fabric, which is a core requirement in the scenario.
- ✗
Fabric edge nodes use OSPF to advertise endpoint host routes into the underlay for reachability.
Why it's wrong here
The SD-Access underlay carries only infrastructure reachability, such as loopbacks and fabric-enabled link networks, using IS-IS. Endpoint host routes are not advertised into the underlay with OSPF. Endpoint reachability is handled in the overlay by LISP, so this statement misrepresents how the fabric scales and how endpoints are resolved.
Visual reference
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco Virtual Topology System
Cisco Virtual Topology System is a software-defined networking solution that creates and manages virtual network overlays across physical and virtual infrastructure for enterprise networks.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.