350-401 Infrastructure Practice Question
A network engineer is troubleshooting a Cisco SD-WAN deployment where a branch router (vEdge) is not forming a control connection with the vSmart controller. The engineer verifies that the vEdge has IP reachability to the vSmart controller's public IP address on port 12346. Which additional step is required for the control connection to be established?
⚠ Common exam trap
The trap here is assuming that IP reachability to the vSmart controller is enough for the control connection, overlooking the mandatory authentication and certificate exchange with the vBond orchestrator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vEdge must have a valid certificate installed and be authenticated by the vBond orchestrator.
For a vEdge to establish a control connection with a vSmart controller, it must first authenticate with the vBond orchestrator using its certificate. This process provides the vEdge with the necessary information, including the vSmart's IP address and credentials to establish the DTLS control connection. IP reachability alone is insufficient.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vEdge must have OSPF configured to advertise its loopback interface to the vSmart controller.
Why it's wrong here
OSPF is not used for control plane connectivity between vEdge and vSmart. The control connection is established over a DTLS tunnel using the public IP. OSPF might be used for data plane routing within the overlay, but it is not required for control connection establishment.
- ✓
The vEdge must have a valid certificate installed and be authenticated by the vBond orchestrator.
Why this is correct
In Cisco SD-WAN, the vEdge router must authenticate with the vBond orchestrator to obtain the list of vSmart controllers and establish control connections. This requires a valid certificate installed during onboarding. Without proper authentication, the vEdge cannot join the overlay network, even if IP reachability exists.
- ✗
The vEdge must be configured with a static route to the vSmart controller's private IP address.
Why it's wrong here
The vSmart controller is typically reached via its public IP address for control connections. A static route to a private IP would not help unless there is a tunnel or NAT in place. The control connection uses the public IP and port 12346, so a static route to a private address is incorrect.
- ✗
The vEdge must be configured with the vSmart controller's IP address as its default gateway.
Why it's wrong here
The default gateway should be the next-hop router for general traffic, not the vSmart controller. The vEdge learns the vSmart controller's address through the vBond orchestrator during the authentication process. Setting the vSmart as the default gateway is not required and would be incorrect.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.