mediumMultiple Choice
350-401 Practice Question: A network team is designing an SD-WAN overlay for…
A network team is designing an SD-WAN overlay for a multinational enterprise with 500+ branch sites. The design must ensure that control plane traffic (e.g., OMP updates) is encrypted and authenticated between all vSmart controllers and vEdge routers, while allowing data plane traffic to use IPsec tunnels between branch sites directly. Which architectural element is responsible for orchestrating the initial authentication and certificate enrollment of all SD-WAN devices?
⚠ Common exam trap
Cisco often tests the misconception that vManage handles all management functions including authentication, but the trap here is that vBond is the dedicated orchestrator for initial trust and certificate enrollment, while vManage only manages the devices after they have been authenticated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vBond
C is correct because the vBond orchestrator is the sole component responsible for initial authentication and certificate enrollment in Cisco SD-WAN. It acts as a trusted certificate authority (CA) proxy, validating the serial numbers and certificates of all vSmart controllers and vEdge routers before they join the overlay network. Without vBond, devices cannot establish trust or receive the authorized list of vSmart and vManage IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vManage
Why it's wrong here
vManage is the centralized management plane of the SD-WAN fabric, providing the GUI for configuration, monitoring, and analytics. It does not perform initial device authentication; rather, it relies on vBond to validate device certificates and introduce the device to the overlay. During onboarding, vManage is contacted only after vBond has established trust, making it a downstream consumer of vBond's authentication, not the authenticator itself.
- ✗
vSmart
Why it's wrong here
vSmart is the control plane component responsible for distributing OMP routes and enforcing centralized policy across the SD-WAN overlay. However, it cannot authenticate a new device because it has no prior trust relationship with the device's identity; vBond performs that initial authentication and then informs vSmart about the newly validated device. vSmart's role is to exchange routing information after the secure channel is established via vBond, so it is dependent on vBond's orchestration, not the initiator of it.
- ✓
vBond
Why this is correct
vBond is the orchestrator and the first point of contact for any device attempting to join the SD-WAN overlay. It authenticates devices by verifying their serial numbers and certificates against the configured credentials, and then provides the authenticated device with the IP addresses of vManage and vSmart. This mutual authentication ensures that only trusted devices can participate, and without vBond, no device can complete the initial handshake to join the fabric.
- ✗
vEdge
Why it's wrong here
vEdge is a data plane router that forwards user traffic at branch or campus sites, and it is itself a tenant of the overlay rather than a controller. It does not authenticate or orchestrate other devices; instead, it is the device that gets authenticated by vBond during its own onboarding process. The vEdge's function is to implement the policies and routes learned from vSmart, so its role is entirely separate from the authentication orchestration performed by vBond.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.