Courseiva
easyMultiple Choice

350-401 Practice Question: A network team is designing an SD-Access fabric…

A network team is designing an SD-Access fabric for a large enterprise. The design must support automated provisioning and policy management. Which management platform is essential for deploying and managing the fabric?

⚠ Common exam trap

Cisco often tests the distinction between management platforms (DNA Center for SD-Access) and policy/identity engines (ISE) or other overlay technologies (vManage for SD-WAN), so the trap here is confusing the role of ISE as a policy enforcer with the role of DNA Center as the fabric orchestrator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco DNA Center

Cisco DNA Center is the essential management platform for deploying and managing an SD-Access fabric because it provides a centralized, intent-based interface for automating the entire fabric lifecycle, including design, provisioning, policy creation, and assurance. It integrates with Cisco ISE for policy enforcement and with network devices via APIs (e.g., NETCONF/YANG) to push configurations such as VXLAN, LISP, and CTS SGTs. Without DNA Center, the automated provisioning and policy management required for SD-Access cannot be achieved at scale.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cisco DNA Center

    Why this is correct

    Cisco DNA Center is the centralized management, automation, and assurance platform that SD-Access is built around. It provides the intent-based fabric provisioning workflows that automatically configure fabric domains, control-plane nodes, border nodes, and edge nodes, while also orchestrating policy definitions and translating business intent into network configuration. Without DNA Center, the fabric underlay and overlay cannot be deployed as a cohesive SD-Access architecture, making it the correct management platform for the fabric.

  • ✗

    Cisco ISE

    Why it's wrong here

    Cisco ISE is the policy and identity engine in an SD-Access deployment, responsible for authentication (802.1X/MAB), authorization, and TrustSec security-group tagging and SGACL enforcement. It integrates with DNA Center to receive policy definitions and provide identity context, but it does not perform fabric automation, device discovery, or underlay/overlay provisioning. ISE's role is policy enforcement, not management of the fabric itself, so it is not the SD-Access management platform.

  • ✗

    Cisco Prime Infrastructure

    Why it's wrong here

    Cisco Prime Infrastructure is a legacy lifecycle management tool for campus and branch devices that predates SD-Access. Although it can manage the underlay switches and offer templates and configuration archives, it lacks the intent-based fabric provisioning capabilities, LISP/VXLAN overlay automation, and DNA Center's design, policy, and assurance workflows needed for SD-Access. Prime Infrastructure cannot create a fabric domain or orchestrate SDA control-plane functions, so it is not an SD-Access management platform in the modern architecture.

  • ✗

    Cisco vManage

    Why it's wrong here

    Cisco vManage is the management plane for Cisco SD-WAN (Viptela) and is used to configure and monitor WAN edge devices, vSmart controllers, vBond orchestrators, and SD-WAN overlay tunnels. SD-Access is a campus LAN technology that uses LISP for control plane and VXLAN for data plane, managed by DNA Center, with no relation to vManage or SD-WAN transport orchestration. vManage cannot provision the fabric, enforce campus security policies, or integrate with ISE at the fabric level, so it is not the SD-Access management platform.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.