mediumMultiple Select
350-401 Practice Question: Which two statements about Cisco DNA Center…
Which two statements about Cisco DNA Center integration with Cisco SD-Access are true? (Choose two.)
⚠ Common exam trap
The trap is confusing the SD-Access fabric control plane protocol (LISP) with the underlay routing protocol (OSPF/IS-IS) — candidates often select OSPF thinking it is the fabric control plane, when LISP is the correct answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco DNA Center is used to design and provision the SD-Access fabric, including defining virtual networks and host pools.
Option A is correct because Cisco DNA Center provides the SD-Access design and provisioning workflow, where the administrator defines the fabric sites, virtual networks (VNs), and host pools that map to IP address pools used for endpoint assignment. Option C is correct because Cisco DNA Center integrates with Cisco Identity Services Engine (ISE) to enforce group-based policies by assigning and propagating Scalable Group Tags (SGTs) through the SD-Access fabric, enabling micro-segmentation via Cisco TrustSec. Option B is incorrect because SD-Access uses LISP as the control plane protocol for the fabric overlay, not OSPF; OSPF or IS-IS may be used as the underlay routing protocol, but DNA Center does not automatically configure OSPF as the SD-Access control plane. Option D is incorrect because SD-Access border nodes are managed directly by Cisco DNA Center as part of the fabric, and no separate WAN controller is required for that purpose. Option E is incorrect because SD-Access edge nodes are access-layer devices that connect endpoints to the fabric, not core routers; the core layer is handled by underlay devices and the fabric's border/control plane nodes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco DNA Center is used to design and provision the SD-Access fabric, including defining virtual networks and host pools.
Why this is correct
Cisco DNA Center provides the design and provisioning workflow for SD-Access, satisfying the stem's requirement. Through its fabric designer, administrators define virtual networks, host pools, and underlay settings, then DNA Center automates device configuration and fabric deployment across the campus, removing manual CLI provisioning.
- ✗
Cisco DNA Center automatically configures OSPF as the control plane protocol for SD-Access.
Why it's wrong here
SD-Access uses LISP for the control plane and VXLAN for data encapsulation; DNA Center does not deploy OSPF as that control plane. OSPF would be the right underlay routing choice, which is why it appears plausible, but it is not the fabric control plane protocol.
- ✓
Cisco DNA Center can enforce group-based policies using Scalable Group Tags (SGTs) in the SD-Access fabric.
Why this is correct
Cisco DNA Center pushes group-based policy into the SD-Access fabric using Scalable Group Tags, satisfying the stem's requirement. SGTs are carried in the VXLAN header, letting the fabric enforce segmentation between endpoint groups without relying on IP-based ACLs, which enables consistent policy across wired and wireless access.
- ✗
Cisco DNA Center requires a separate WAN controller to manage SD-Access border nodes.
Why it's wrong here
Cisco DNA Center itself manages SD-Access fabric devices, including border nodes, so no separate WAN controller is needed. A distinct WAN controller would be relevant only for managing WAN edge routing in a separate SD-WAN deployment, not for fabric border control.
- ✗
Cisco DNA Center configures SD-Access edge nodes as the core routers of the network.
Why it's wrong here
Edge nodes provide fabric access for endpoints; the core routers are the underlay devices, so DNA Center does not configure edges as core routers. Confusing the roles is tempting because edges do forward traffic, but the correct answer assigns core routing to the underlay.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
VLANs and Spanning Tree Protocol Concepts
Key term
Cisco SD-Access
Cisco Software-Defined Access is a network architecture that uses a central controller to automate and secure user and device access across an enterprise network.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.