Courseiva
mediumMultiple Choice

350-401 Practice Question: A network team is designing an SD-WAN overlay for…

A network team is designing an SD-WAN overlay for a multinational enterprise with 500+ branch sites. The design must ensure that control plane traffic (e.g., OMP updates) is encrypted and authenticated between all vSmart controllers and vEdge routers, while allowing data plane traffic to use IPsec tunnels between branch sites directly. Which architectural element is responsible for orchestrating the initial authentication and certificate enrollment of all SD-WAN devices?

⚠ Common exam trap

Cisco often tests the misconception that vManage handles all management functions including authentication, but the trap here is that vBond is the dedicated orchestrator for initial trust and certificate enrollment, while vManage only manages the devices after they have been authenticated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vBond

C is correct because the vBond orchestrator is the sole component responsible for initial authentication and certificate enrollment in Cisco SD-WAN. It acts as a trusted certificate authority (CA) proxy, validating the serial numbers and certificates of all vSmart controllers and vEdge routers before they join the overlay network. Without vBond, devices cannot establish trust or receive the authorized list of vSmart and vManage IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vManage

    Why it's wrong here

    vManage is the centralized management plane of the SD-WAN fabric, providing the GUI for configuration, monitoring, and analytics. It does not perform initial device authentication; rather, it relies on vBond to validate device certificates and introduce the device to the overlay. During onboarding, vManage is contacted only after vBond has established trust, making it a downstream consumer of vBond's authentication, not the authenticator itself.

  • ✗

    vSmart

    Why it's wrong here

    vSmart is the control plane component responsible for distributing OMP routes and enforcing centralized policy across the SD-WAN overlay. However, it cannot authenticate a new device because it has no prior trust relationship with the device's identity; vBond performs that initial authentication and then informs vSmart about the newly validated device. vSmart's role is to exchange routing information after the secure channel is established via vBond, so it is dependent on vBond's orchestration, not the initiator of it.

  • ✓

    vBond

    Why this is correct

    vBond is the orchestrator and the first point of contact for any device attempting to join the SD-WAN overlay. It authenticates devices by verifying their serial numbers and certificates against the configured credentials, and then provides the authenticated device with the IP addresses of vManage and vSmart. This mutual authentication ensures that only trusted devices can participate, and without vBond, no device can complete the initial handshake to join the fabric.

  • ✗

    vEdge

    Why it's wrong here

    vEdge is a data plane router that forwards user traffic at branch or campus sites, and it is itself a tenant of the overlay rather than a controller. It does not authenticate or orchestrate other devices; instead, it is the device that gets authenticated by vBond during its own onboarding process. The vEdge's function is to implement the policies and routes learned from vSmart, so its role is entirely separate from the authentication orchestration performed by vBond.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.