easyMultiple Choice
350-401 Practice Question: A network team is designing an SD-Access fabric…
A network team is designing an SD-Access fabric for a large enterprise. The design must support automated provisioning and policy management. Which management platform is essential for deploying and managing the fabric?
⚠ Common exam trap
Cisco often tests the distinction between management platforms (DNA Center for SD-Access) and policy/identity engines (ISE) or other overlay technologies (vManage for SD-WAN), so the trap here is confusing the role of ISE as a policy enforcer with the role of DNA Center as the fabric orchestrator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco DNA Center
Cisco DNA Center is the essential management platform for deploying and managing an SD-Access fabric because it provides a centralized, intent-based interface for automating the entire fabric lifecycle, including design, provisioning, policy creation, and assurance. It integrates with Cisco ISE for policy enforcement and with network devices via APIs (e.g., NETCONF/YANG) to push configurations such as VXLAN, LISP, and CTS SGTs. Without DNA Center, the automated provisioning and policy management required for SD-Access cannot be achieved at scale.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco DNA Center
Why this is correct
Cisco DNA Center is the centralized management, automation, and assurance platform that SD-Access is built around. It provides the intent-based fabric provisioning workflows that automatically configure fabric domains, control-plane nodes, border nodes, and edge nodes, while also orchestrating policy definitions and translating business intent into network configuration. Without DNA Center, the fabric underlay and overlay cannot be deployed as a cohesive SD-Access architecture, making it the correct management platform for the fabric.
- ✗
Cisco ISE
Why it's wrong here
Cisco ISE is the policy and identity engine in an SD-Access deployment, responsible for authentication (802.1X/MAB), authorization, and TrustSec security-group tagging and SGACL enforcement. It integrates with DNA Center to receive policy definitions and provide identity context, but it does not perform fabric automation, device discovery, or underlay/overlay provisioning. ISE's role is policy enforcement, not management of the fabric itself, so it is not the SD-Access management platform.
- ✗
Cisco Prime Infrastructure
Why it's wrong here
Cisco Prime Infrastructure is a legacy lifecycle management tool for campus and branch devices that predates SD-Access. Although it can manage the underlay switches and offer templates and configuration archives, it lacks the intent-based fabric provisioning capabilities, LISP/VXLAN overlay automation, and DNA Center's design, policy, and assurance workflows needed for SD-Access. Prime Infrastructure cannot create a fabric domain or orchestrate SDA control-plane functions, so it is not an SD-Access management platform in the modern architecture.
- ✗
Cisco vManage
Why it's wrong here
Cisco vManage is the management plane for Cisco SD-WAN (Viptela) and is used to configure and monitor WAN edge devices, vSmart controllers, vBond orchestrators, and SD-WAN overlay tunnels. SD-Access is a campus LAN technology that uses LISP for control plane and VXLAN for data plane, managed by DNA Center, with no relation to vManage or SD-WAN transport orchestration. vManage cannot provision the fabric, enforce campus security policies, or integrate with ISE at the fabric level, so it is not the SD-Access management platform.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.