mediumMultiple Select
350-401 Practice Question: Which two statements about the Cisco Enterprise…
Which two statements about the Cisco Enterprise Campus Architecture are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the misconception that the core layer should enforce security or that the access layer performs inter-VLAN routing, confusing the roles of each tier in the hierarchical model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The distribution layer provides policy-based connectivity and controls traffic flow between access and core layers.
Option A is correct because in the Cisco Enterprise Campus Architecture the distribution layer is the aggregation point that provides policy-based connectivity, inter-VLAN routing, route summarization, and controls traffic flow between the access and core layers. Option C is correct because the core layer is designed as a high-speed transport backbone with minimal latency, so CPU-intensive features such as ACLs, packet inspection, and policy enforcement should be avoided there. Option B is wrong because routing between VLANs and high-speed backbone switching are functions of the distribution and core layers, not the access layer, which primarily provides user/device connectivity and Layer 2 switching with PoE and port security. Option D is wrong because a two-tier collapsed-core design is recommended for smaller campus networks, whereas large campuses with thousands of users typically use a three-tier hierarchical design. Option E is wrong because security policy enforcement and packet inspection belong at the distribution (and access) layers, not the core, which must remain fast and simple.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The distribution layer provides policy-based connectivity and controls traffic flow between access and core layers.
Why this is correct
The distribution layer aggregates access switches and enforces policy, performing inter-VLAN routing, filtering and QoS between access and core. This satisfies the requirement for policy-based connectivity and traffic-flow control, keeping the core free for high-speed transport.
- ✗
The access layer is responsible for routing between VLANs and providing high-speed switching for the campus backbone.
Why it's wrong here
Inter-VLAN routing and high-speed backbone switching are distribution-layer and core-layer functions respectively; the access layer provides port density and connects endpoints. It tempts because access switches do forward frames, but routing between VLANs occurs one layer up.
- ✓
The core layer should be designed for high-speed transport and minimal latency, avoiding CPU-intensive features like ACLs.
Why this is correct
The core layer exists purely as a high-speed transport backbone between distribution blocks, so latency-sensitive forwarding is prioritised. Deferring ACLs, policing and other CPU-intensive policy enforcement to the distribution layer preserves core switching throughput and avoids introducing forwarding delays.
- ✗
A two-tier hierarchical design (collapsed core) is recommended for large campus networks with thousands of users.
Why it's wrong here
A two-tier collapsed core design lacks the dedicated core layer needed to handle the high-density routing and east-west traffic demands of thousands of users; large campus networks require a three-tier architecture with a separate core to provide sufficient forwarding capacity and redundancy. This option is tempting because a collapsed core works well for smaller or medium-sized campuses where the distribution and core functions can be combined without overwhelming the switch fabric.
- ✗
The core layer should enforce security policies and perform packet inspection to protect the campus network.
Why it's wrong here
Security policy enforcement and packet inspection belong to the distribution or access layer, where policy boundaries sit; the core's role is high-speed, low-latency transport between distribution blocks. It tempts because core devices are powerful, but inspection there would throttle the backbone.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Switch Virtual Interface
A logical interface on a network switch that allows it to be managed and communicate with other devices using IP addresses.
Key term
L2 Security Features
L2 Security Features are network security mechanisms that operate at Layer 2 of the OSI model to protect local network traffic from threats like MAC spoofing, ARP attacks, and unauthorized access.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.