350-401 Architecture Practice Question
A network engineer is designing a network that uses Cisco SD-Access with a fabric that includes a border node and control plane node. The engineer must ensure that traffic from external networks can reach endpoints within the fabric. Which function does the border node provide in this architecture?
⚠ Common exam trap
A common mix-up: candidates confuse the border node's external connectivity role with the control plane node's mapping role or the edge node's gateway role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides connectivity between the fabric and external networks, such as WAN or data center.
The border node in Cisco SD-Access provides connectivity between the fabric and external networks, handling traffic entering and leaving the fabric. It performs VXLAN-to-VLAN translation and routing, enabling external users to reach fabric endpoints. This is distinct from the control plane node's mapping function and the edge node's policy enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It provides connectivity between the fabric and external networks, such as WAN or data center.
Why this is correct
The border node in Cisco SD-Access provides connectivity between the fabric and external networks. It handles traffic entering and leaving the fabric, performing functions such as VXLAN-to-VLAN translation and routing to external networks. This allows external users to reach fabric endpoints.
- ✗
It maintains the mapping of endpoint IP addresses to fabric edge nodes.
Why it's wrong here
The control plane node, not the border node, maintains the endpoint-to-edge node mappings using LISP. The border node handles external connectivity and does not perform the mapping function. This option describes the control plane node's role.
- ✗
It enforces security policies between endpoints within the same virtual network.
Why it's wrong here
Security policy enforcement within a virtual network is performed by fabric edge nodes using SGTs, not by the border node. The border node focuses on external connectivity and may apply policies for traffic entering or leaving the fabric, but not for intra-VN traffic.
- ✗
It acts as the default gateway for all endpoints in the fabric.
Why it's wrong here
The default gateway for endpoints is typically the fabric edge node to which they are connected. The border node does not serve as the default gateway for endpoints; it provides external connectivity and may be the gateway for external networks to reach the fabric.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Architecture Fundamentals
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
Key term
Cisco SD-Access
Cisco Software-Defined Access is a network architecture that uses a central controller to automate and secure user and device access across an enterprise network.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.