Courseiva
mediumMultiple Choice

350-401 Practice Question: An architect is designing an SD-Access fabric for…

An architect is designing an SD-Access fabric for a large enterprise campus. The design must support segmentation based on user identity and device type, and must integrate with Cisco ISE. Which fabric component and protocol should be used to enforce micro-segmentation?

⚠ Common exam trap

Cisco often tests the distinction between macro-segmentation (VXLAN/VRF) and micro-segmentation (SGT/TrustSec), and the trap here is assuming VXLAN with BGP EVPN alone provides identity-based segmentation, when it only creates separate overlay networks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Cisco TrustSec with SGTs and integrate with ISE.

Cisco TrustSec with Security Group Tags (SGTs) is the correct choice because it provides identity- and device-type-based micro-segmentation in an SD-Access fabric. SGTs are assigned by Cisco ISE based on user/device attributes, and the fabric enforces policies by tagging packets with SGTs, allowing granular traffic filtering regardless of IP address or VLAN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use VXLAN with BGP EVPN for segmentation.

    Why it's wrong here

    VXLAN with BGP EVPN can extend Layer 2/Layer 3 domains across the fabric and enforce segmentation at the network layer using VNIs, but it does not natively transport a metadata tag that reflects user or device identity. Even when EVPN provides host routes and MAC/IP mobility, the forwarding policy is tied to VNI or IP subnet rather than to a dynamic security group. Without a mechanism like SGT (which can be carried in VXLAN when integrated with TrustSec) the result is coarse network segmentation, not identity-based micro-segmentation.

  • ✓

    Deploy Cisco TrustSec with SGTs and integrate with ISE.

    Why this is correct

    Cisco TrustSec uses Security Group Tags (SGTs) assigned by ISE based on identity, endpoint posture, and other policy attributes, not on IP addressing or VLAN topology. The data plane enforces micro-segmentation through SGACLs that permit or deny traffic between source and destination SGTs, even within the same broadcast domain. ISE acts as the policy management and classification engine, dynamically updating SGT assignments and distributing access policies. Because enforcement is per security group and stateful across the overlay, this directly delivers identity-based micro-segmentation.

  • ✗

    Use LISP to map endpoints to virtual networks.

    Why it's wrong here

    LISP separates endpoint identifiers (EIDs) from routing locators (RLOCs) and can map endpoints to virtual networks using LISP instance IDs, but this is primarily a control-plane function for overlay mobility and location/identity separation. LISP itself does not attach security-group metadata to packets or enforce per-group, per-endpoint policies at every hop. EID-driven policies are still topological (e.g., EID-prefix or VRF) and are not dynamically tied to a user's identity or post-auth posture. Therefore LISP alone cannot provide the identity-based micro-segmentation required here.

  • ✗

    Implement VLAN-based segmentation with 802.1X.

    Why it's wrong here

    802.1X with VLAN assignment authenticates an endpoint and places it into a designated VLAN, but once the device is in that VLAN all traffic is treated under one coarse policy, sharing the same broadcast domain and ACL boundaries. VLANs are limited to 4094 for standard 802.1Q and are not designed to carry per-session trust metadata, so dynamic identity changes require re-authentication and VLAN reassignment. The policy is tied to the Layer 2 segment, not to the user/device identity after authentication, and this becomes operationally rigid in a fabric where micro-segmentation demands per-group enforcement independent of subnet or VLAN placement.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.