Courseiva
mediumMultiple Choice

350-401 Practice Question: Deploying an SD-Access fabric with multiple sites…

A company is deploying an SD-Access fabric with multiple sites connected via a WAN. The design must allow inter-site traffic to be forwarded without requiring a full mesh of VXLAN tunnels between all edge nodes. Which fabric role should be used to interconnect the sites?

⚠ Common exam trap

Cisco often tests the misconception that a Fabric Edge Node can directly forward traffic between sites, but the trap here is that Edge Nodes only handle intra-site VXLAN tunnels and rely on Border Nodes for any traffic leaving the fabric site.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fabric border node

A Fabric Border Node is the correct role because it acts as the gateway between the SD-Access fabric and external networks, including WAN connections. It performs Network-to-Network Interconnection (NNI) by translating VXLAN-encapsulated traffic into the appropriate WAN transport (e.g., IPsec, MPLS) and handles inter-site routing without requiring a full mesh of VXLAN tunnels between all Edge Nodes. This design leverages the Border Node to aggregate traffic and forward it over the WAN, reducing tunnel overhead and simplifying the fabric architecture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Fabric border node

    Why this is correct

    In SD-Access, border nodes connect the fabric to external Layer 3 networks (e.g., WAN, data center, Internet) by translating VXLAN encapsulated traffic to traditional routing. They advertise fabric IP prefixes externally and support inter-site VXLAN data plane, handling north-south and east-west inter-site traffic. They also enforce policy and host the LISP control plane for external reachability.

  • ✗

    Fabric control plane node

    Why it's wrong here

    In SD-Access, control plane nodes run LISP Map-Server/Resolver to maintain the EID-to-RLOC database, tracking which fabric edge node hosts each endpoint. They respond to map-requests to resolve destination endpoints, but they never sit in the data plane; all actual traffic forwarding, including inter-site flows, occurs through edge and border nodes. Therefore, they cannot act as the inter-site gateway.

  • ✗

    Fabric edge node

    Why it's wrong here

    Fabric edge nodes are the access-layer switches that physically attach wired endpoints (clients, servers, APs) to the SD-Access fabric. They encapsulate endpoint traffic into VXLAN with the destination's RLOC (routing locator) and forward it via the fabric, but they do not advertise or route prefixes outside the fabric domain. Inter-site connectivity requires a border node to egress the VXLAN fabric and perform external routing functions; edge nodes only handle local site endpoint traffic.

  • ✗

    Fabric WAN controller

    Why it's wrong here

    Cisco SD-Access does not define a separate "WAN controller" role within the fabric architecture; the SD-Access fabric is composed of edge, control plane, and border nodes as its primary roles. WAN connectivity and inter-site traffic are the responsibility of border nodes, which can be configured as either default or internal border nodes to connect to external networks or shared services. Thus, selecting a non-existent role misunderstands the fabric's component taxonomy.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.