hardMultiple Choice
350-401 Practice Question: An architect is designing a QoS policy for a…
An architect is designing a QoS policy for a Cisco SD-Access fabric. The policy must prioritize voice traffic from wireless clients connected to fabric-enabled access points over other traffic types. The design should use the fabric's built-in capabilities to simplify deployment. Which approach should the architect take?
⚠ Common exam trap
Cisco often tests the misconception that QoS marking alone (e.g., DSCP EF) is sufficient in SD-Access, when in fact the fabric requires explicit policy enforcement at the edge node, and SGT-based classification is the recommended method for scalable, identity-aware QoS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Cisco TrustSec to assign an SGT to voice traffic based on ISE authentication, then apply a QoS policy on the fabric edge node that matches the SGT and provides priority queuing.
Cisco SD-Access uses TrustSec to propagate Security Group Tags (SGTs) from ISE to the fabric edge nodes. By matching the SGT assigned to voice traffic (e.g., via ISE profiling and authentication), the fabric edge node can apply a QoS policy that places that traffic into a priority queue. This leverages the fabric's built-in SGT-based policy enforcement, simplifying deployment without requiring per-device ACLs or complex marking configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Cisco TrustSec to assign an SGT to voice traffic based on ISE authentication, then apply a QoS policy on the fabric edge node that matches the SGT and provides priority queuing.
Why this is correct
In an SD-Access fabric, Cisco TrustSec enables ISE to assign an SGT to an authenticated IP phone, identifying it as voice even when its IP address changes. The fabric edge node, as the first hop for the voice traffic, can match that SGT and apply a policy that marks DSCP EF and places packets into the priority queue. Because SGT-based classification is independent of IP addressing, it scales cleanly and provides consistent queuing as the traffic traverses the fabric.
- ✗
Configure QoS policies on the wireless LAN controller (WLC) only, marking voice traffic with DSCP EF, and rely on the fabric to preserve the marking.
Why it's wrong here
Marking voice traffic with DSCP EF on the WLC is only the classification step; the fabric edge must still trust or re-classify that marking and enqueue the traffic appropriately. Relying solely on the fabric to preserve DSCP does not guarantee priority queuing, because the fabric edge might ignore the DSCP value or lack an explicit policy. This approach also ignores SGT-based segmentation, which would tie QoS to authenticated device identity rather than a network header field.
- ✗
Implement a centralized QoS policy on the fabric border node that matches the source IP addresses of voice devices.
Why it's wrong here
Applying QoS on the fabric border node would affect only traffic destined outside the fabric, while most internal voice traffic never traverses the border node. Source IP matching is fragile—phones may use DHCP, move across sites, or sit behind NAT—and it lacks the identity context that SGT provides. Classification must happen at the fabric edge where traffic enters the trust boundary, so queuing can be applied before the packet is forwarded toward its destination.
- ✗
Use VXLAN network identifiers (VNIs) to classify voice traffic and apply QoS on the control plane node.
Why it's wrong here
VNIs separate tenant traffic in the overlay, but they are not QoS classification fields; multiple applications share a VNI and cannot be differentiated by it. Moreover, the control plane node (LISP map-server/parallel) is not in the forwarding path, so any QoS policy configured there will never process data traffic. QoS actions such as marking and queuing must be configured on the fabric edge or fabric intermediate nodes that actually handle the voice packets.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco SD-Access
Cisco Software-Defined Access is a network architecture that uses a central controller to automate and secure user and device access across an enterprise network.
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.