mediumMultiple Choice
350-401 Practice Question: Deploying an SD-Access fabric with multiple sites…
A company is deploying an SD-Access fabric with multiple sites connected via a WAN. The design must allow inter-site traffic to be forwarded without requiring a full mesh of VXLAN tunnels between all edge nodes. Which fabric role should be used to interconnect the sites?
⚠ Common exam trap
Cisco often tests the misconception that a Fabric Edge Node can directly forward traffic between sites, but the trap here is that Edge Nodes only handle intra-site VXLAN tunnels and rely on Border Nodes for any traffic leaving the fabric site.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fabric border node
A Fabric Border Node is the correct role because it acts as the gateway between the SD-Access fabric and external networks, including WAN connections. It performs Network-to-Network Interconnection (NNI) by translating VXLAN-encapsulated traffic into the appropriate WAN transport (e.g., IPsec, MPLS) and handles inter-site routing without requiring a full mesh of VXLAN tunnels between all Edge Nodes. This design leverages the Border Node to aggregate traffic and forward it over the WAN, reducing tunnel overhead and simplifying the fabric architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Fabric border node
Why this is correct
In SD-Access, border nodes connect the fabric to external Layer 3 networks (e.g., WAN, data center, Internet) by translating VXLAN encapsulated traffic to traditional routing. They advertise fabric IP prefixes externally and support inter-site VXLAN data plane, handling north-south and east-west inter-site traffic. They also enforce policy and host the LISP control plane for external reachability.
- ✗
Fabric control plane node
Why it's wrong here
In SD-Access, control plane nodes run LISP Map-Server/Resolver to maintain the EID-to-RLOC database, tracking which fabric edge node hosts each endpoint. They respond to map-requests to resolve destination endpoints, but they never sit in the data plane; all actual traffic forwarding, including inter-site flows, occurs through edge and border nodes. Therefore, they cannot act as the inter-site gateway.
- ✗
Fabric edge node
Why it's wrong here
Fabric edge nodes are the access-layer switches that physically attach wired endpoints (clients, servers, APs) to the SD-Access fabric. They encapsulate endpoint traffic into VXLAN with the destination's RLOC (routing locator) and forward it via the fabric, but they do not advertise or route prefixes outside the fabric domain. Inter-site connectivity requires a border node to egress the VXLAN fabric and perform external routing functions; edge nodes only handle local site endpoint traffic.
- ✗
Fabric WAN controller
Why it's wrong here
Cisco SD-Access does not define a separate "WAN controller" role within the fabric architecture; the SD-Access fabric is composed of edge, control plane, and border nodes as its primary roles. WAN connectivity and inter-site traffic are the responsibility of border nodes, which can be configured as either default or internal border nodes to connect to external networks or shared services. Thus, selecting a non-existent role misunderstands the fabric's component taxonomy.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
Key term
Cisco Virtual Topology System
Cisco Virtual Topology System is a software-defined networking solution that creates and manages virtual network overlays across physical and virtual infrastructure for enterprise networks.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.