mediumMultiple Choice
350-401 Practice Question: A network architect is designing QoS for a Cisco…
A network architect is designing QoS for a Cisco SD-WAN deployment that uses a mix of MPLS and broadband Internet transports. The design must ensure that interactive video traffic is not delayed by large file transfers, even when the Internet link experiences congestion. Which SD-WAN policy type should the architect use to enforce this behavior?
⚠ Common exam trap
Cisco often tests the distinction between traffic-steering policies (centralized data or app-aware routing) and local queuing mechanisms (QoS policies), leading candidates to mistakenly choose a path-selection solution when the question explicitly asks about preventing delay on a congested link.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a localized QoS policy on the WAN edge routers that matches video traffic and applies a priority queue.
A localized QoS policy on the WAN edge router can classify interactive video traffic and place it into a priority queue, ensuring low-latency treatment even when the Internet link is congested. This policy operates locally on the router, directly controlling queuing and scheduling behavior on the specific interface, which is essential for protecting real-time traffic from bulk file transfers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a localized QoS policy on the WAN edge routers that matches video traffic and applies a priority queue.
Why this is correct
Localized QoS policies are attached directly to the WAN edge router's egress interface, where congestion actually occurs. Within the policy-map, you create a class dedicated to video (matched via DSCP EF or NBAR) and assign it strict priority using the 'priority' command, which yields low-latency queuing (LLQ). This ensures video packets are dequeued before bulk traffic at every hop, directly minimizing jitter and end-to-end delay on each link. Unlike path-selection or isolation approaches, this provides a per-interface bandwidth guarantee that survives regardless of which transport is used.
- ✗
Use a centralized data policy to steer video traffic to the MPLS link only.
Why it's wrong here
A centralized data policy in SD-WAN steers traffic by tweaking route maps or similar constructs, but it only changes which interface a packet leaves on—it does not create queues or modify scheduler behavior. Forcing all video onto the MPLS link removes that traffic from the Internet link, yet does nothing to protect video when the MPLS egress becomes saturated; the moment MPLS is congested, video still waits behind best-effort packets. Moreover, if the Internet link is idle, its queueing resources are wasted, and any video that unavoidably lands there (e.g., due to a failover) will have zero priority treatment.
- ✗
Implement a centralized application-aware routing policy to prefer the MPLS link for video.
Why it's wrong here
Application-aware routing uses a centralized controller to evaluate real-time SLA metrics (loss, latency, jitter) and steer application flows to the best-performing path, making it a routing optimization feature rather than a QoS one. Even when it prefers MPLS for video, the policy only influences per-flow path selection; the egress interface's default queuing structure (typically FIFO or a plain class map without priority) remains intact, so video competes equally with data during congestion. This approach also assumes MPLS always has spare capacity—if it does not, the controller might revert to the Internet transport, again leaving video unprotected from queuing delay.
- ✗
Configure a VPN membership policy to isolate video traffic in a separate VPN.
Why it's wrong here
A VPN membership policy is a control-plane construct that assigns VRF or overlay network membership, separating routing tables and, at most, applying encryption/decryption contexts. It does not alter the data-plane queuing behavior on physical interfaces: traffic from all VPNs that egress the same WAN router is serialized into the same hardware queue, and without a service-policy, FIFO scheduling applies. Isolating video in a dedicated VPN might give it a distinct forwarding table, but it neither reserves bandwidth nor prioritizes frames, and the added encapsulation overhead can actually exacerbate delay for real-time flows.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.