Courseiva
mediumMultiple Choice

350-401 Practice Question: An enterprise is deploying Cisco SD-WAN and must…

An enterprise is deploying Cisco SD-WAN and must ensure that data plane traffic between branch sites is encrypted and authenticated. The design must also allow the use of application-aware routing to steer traffic based on real-time performance metrics. Which component is responsible for establishing and managing the IPsec tunnels between branch routers?

⚠ Common exam trap

Cisco often tests the misconception that vSmart controllers handle all tunnel management, but in SD-WAN, vSmart only distributes policies and OMP routes, while the actual IPsec tunnel establishment and data plane forwarding is a function of the vEdge/cEdge routers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vEdge/cEdge routers

The vEdge/cEdge routers are the correct answer because they are the SD-WAN edge devices that terminate IPsec tunnels for data plane traffic. In Cisco SD-WAN, the data plane is fully distributed: each vEdge or cEdge router establishes and manages its own IPsec tunnels (using DTLS/TLS for control and IPsec for data) directly with other branch routers. This allows the routers to apply application-aware routing by monitoring real-time performance metrics (e.g., loss, latency, jitter) and steering traffic across the encrypted tunnels accordingly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vSmart controllers

    Why it's wrong here

    vSmart controllers are a central component of the SD-WAN control plane, responsible for running OMP (Overlay Management Protocol) to exchange routing information and security policies with vEdge/cEdge routers. They maintain control connections using DTLS or TLS, but they never sit in the data forwarding path and do not terminate IPsec tunnels that carry user traffic. Since they only manage routes and policies, they cannot be the correct answer for data plane tunnel termination.

  • ✓

    vEdge/cEdge routers

    Why this is correct

    vEdge and cEdge routers are the SD-WAN edge devices that physically anchor the branch network and handle user data forwarding. After receiving OMP routes from vSmart, they dynamically negotiate and terminate secure IPsec data plane tunnels across the underlay network, encrypting each packet and applying application-aware routing and QoS decisions. Without these edge routers, no overlay data traffic can be forwarded or encrypted, making them the only listed component responsible for IPsec tunnel establishment at the data plane.

  • ✗

    vManage

    Why it's wrong here

    vManage serves as the central network management system (NMS) in Cisco SD-WAN, offering a graphical dashboard for configuration, telemetry, software updates, and monitoring. It communicates with all devices over management protocols like NETCONF or RESTCONF to push configurations and collect operational data, but it never inspects or forwards user data packets. Since it does not hold any IPsec security associations or participate in overlay forwarding, it is not the device that terminates data plane tunnels.

  • ✗

    vBond

    Why it's wrong here

    vBond is the orchestrator that performs the initial onboarding and authentication of all SD-WAN controllers and edge devices, distributing certificates and resolving NAT traversal by identifying public IP addresses. After this bootstrap phase, vBond exits the control path and is not involved in ongoing data forwarding, nor does it establish or maintain IPsec data plane tunnels. Its role is limited to first-contact discovery and security authentication, so it cannot be the answer for IPsec tunnel termination.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.