Courseiva
Virtualization →mediumMultiple Choice

350-401 Virtualization Practice Question

A network engineer is deploying a Cisco SD-Access fabric. The design requires that endpoints be authenticated and assigned to a VLAN and VRF based on their identity before any traffic is forwarded. Which Cisco SD-Access component is responsible for this function?

⚠ Common exam trap

The trap here is assuming the fabric edge node or control plane node performs endpoint authentication and VLAN/VRF assignment, when that is actually the role of Cisco ISE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco Identity Services Engine

Cisco ISE is the identity services component that authenticates endpoints and returns the VLAN and VRF assignment to the fabric edge node. The edge node then places the endpoint into the correct virtual network and applies group-based policy. Neither the control plane nor border nodes perform authentication or endpoint classification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cisco Identity Services Engine

    Why this is correct

    Cisco ISE authenticates endpoints using 802.1X, MAC authentication bypass, or web authentication, and returns the VLAN and VRF (or SGT) assignment to the fabric edge node. This is the identity services function that enforces policy before forwarding.

  • ✗

    Fabric border node

    Why it's wrong here

    The border node provides connectivity between the SD-Access fabric and external networks, such as the data center or WAN. It handles VXLAN-to-VLAN or VRF-lite handoff and does not authenticate endpoints or assign them to VLANs or VRFs.

  • ✗

    Fabric control plane node

    Why it's wrong here

    The control plane node maintains the endpoint-to-edge-node mapping in the LISP map-server and map-resolver. It answers location queries but does not authenticate endpoints or decide which VLAN or VRF they belong to; that assignment is made by the identity services engine.

  • ✗

    Fabric edge node

    Why it's wrong here

    The fabric edge node encapsulates VXLAN traffic and enforces policy, but it relies on the control plane and identity services to determine the endpoint's group. It does not independently perform authentication or assign VLAN/VRF; it receives that mapping from the fabric control plane and identity services.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.