350-401 Architecture Practice Question
A network engineer is implementing Cisco SD-Access and needs to understand the role of the LISP protocol. Which statement accurately describes the function of LISP in SD-Access?
⚠ Common exam trap
It's easy for candidates to confuse LISP with VXLAN, assuming LISP provides data plane encapsulation when it actually provides control plane mapping.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LISP provides the control plane for mapping endpoint identities to their locations.
LISP in SD-Access acts as the control plane, separating endpoint identity from location. It maintains a mapping database that fabric edge nodes query to resolve EID-to-RLOC mappings, enabling scalable endpoint mobility and fabric operations. The data plane uses VXLAN, while policy is enforced via TrustSec SGTs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LISP dynamically assigns IP addresses to endpoints in the fabric.
Why it's wrong here
IP address assignment in SD-Access is typically handled by DHCP, often integrated with Cisco DNA Center or external servers. LISP does not assign IP addresses; it maps already-assigned endpoint IP addresses (EIDs) to fabric edge nodes (RLOCs). Its role is location resolution, not address allocation.
- ✗
LISP enforces security policies between fabric segments.
Why it's wrong here
Security policy enforcement in SD-Access is handled by Cisco TrustSec and Scalable Group Tags (SGTs), which are carried in VXLAN headers. LISP is not responsible for policy enforcement; it provides the mapping service that allows fabric devices to locate endpoints. Policy is applied based on group tags, not LISP mappings.
- ✗
LISP is used for data plane encapsulation between fabric nodes.
Why it's wrong here
The data plane encapsulation in SD-Access is VXLAN, not LISP. LISP handles the control plane by resolving EID-to-RLOC mappings, while VXLAN encapsulates the original IP packets for transport across the fabric. Confusing LISP with the data plane is a common error; LISP itself does not encapsulate user data in SD-Access.
- ✓
LISP provides the control plane for mapping endpoint identities to their locations.
Why this is correct
In Cisco SD-Access, LISP (Locator/ID Separation Protocol) serves as the control plane protocol that separates endpoint identity (EID) from its location (RLOC). It maintains a mapping database that allows fabric edge nodes to query the mapping system to locate endpoints. This enables scalable, dynamic endpoint mobility and policy enforcement across the fabric.
Visual reference
Go deeper
Related to this question
Learn chapter
VLANs and Spanning Tree Protocol Concepts
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
Key term
Cisco SD-Access
Cisco Software-Defined Access is a network architecture that uses a central controller to automate and secure user and device access across an enterprise network.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.