Courseiva
hardMultiple Choice

350-401 Practice Question: An enterprise is migrating from a traditional…

An enterprise is migrating from a traditional three-tier campus design to a software-defined access (SD-Access) fabric. The engineer needs to ensure that the existing wireless infrastructure integrates seamlessly. Which component of SD-Access is responsible for integrating wireless and wired policies?

⚠ Common exam trap

Cisco often tests the misconception that the WLC is responsible for policy integration, but in SD-Access, the WLC is merely a wireless controller that tunnels client traffic to the Fabric Edge node, which is the actual policy enforcement point.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fabric Edge node

The Fabric Edge node is the correct answer because it is the SD-Access component that serves as the attachment point for both wired and wireless endpoints. In an SD-Access fabric, the Fabric Edge node terminates the VXLAN tunnels from the wireless LAN controller (WLC) and applies consistent policy (e.g., SGT-based ACLs) to traffic from both wired and wireless users, ensuring seamless integration of the existing wireless infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Fabric Edge node

    Why this is correct

    The Fabric Edge node is the ingress point for every endpoint—wired or wireless—into the SD-Access fabric. It terminates VXLAN tunnels from access switches and wireless APs, hosts the anycast gateway for the subnet, and enforces policy via Cisco TrustSec (SGT-based segmentation) and ACLs. All user traffic enters here, making it the correct component for integrating policies and providing connectivity.

  • ✗

    Fabric Control node

    Why it's wrong here

    The Fabric Control node is the LISP control plane responsible for maintaining the Endpoint Identifier (EID) to Routing Locator (RLOC) mappings. It does not physically attach to any endpoints; wireless clients are registered with the Control node through the Fabric Edge, which discovers them. Since it only provides mapping and registration services, it cannot directly integrate or enforce policies on user traffic.

  • ✗

    Fabric Border node

    Why it's wrong here

    The Fabric Border node serves as the exit or entry point between the SD-Access fabric and external networks such as a WAN or the Internet. It translates VXLAN encapsulated traffic to traditional IP routing and applies inter-VRF routing policies for north-south flows, but it never terminates wireless user connections. Wireless endpoints are always attached to a Fabric Edge node, not a Border node.

  • ✗

    Wireless LAN Controller (WLC)

    Why it's wrong here

    While the Wireless LAN Controller (WLC) manages access points, handles RF, and supports roaming, in an SD-Access deployment it does not enforce segmentation or policy on wireless clients. The WLC forwards wireless traffic to the Fabric Edge, which applies VXLAN encapsulation, SGT-based policy, and anycast gateway features. Therefore, the WLC is a management component, not the policy-integration point for wireless users.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.