hardMultiple Select
SD-Access Policy Enforcement
Which three statements about Cisco SD-Access policy enforcement are true? (Choose three.)
Quick Answer
The correct answer identifies that SGT information is carried in the VXLAN header using the Group Policy Option (GPO). This is true because Cisco SD-Access policy enforcement relies on Scalable Group Tags (SGTs) for micro-segmentation, with policies defined in Cisco ISE and enforced at the fabric edge node. The fabric edge applies SGT-based ACLs to traffic, while the control plane (LISP) distributes SGT mappings but does not enforce policies—that role belongs solely to the edge. On the ENCOR 350-401 exam, this concept tests your understanding of where policy enforcement actually occurs, with a common trap being to assume the border node or underlay handles SGT enforcement. Remember: the underlay is completely SGT-unaware, and the border only manages external connectivity. A useful memory tip is “Edge enforces, border exits”—the fabric edge is where SGT-based policy decisions happen, and the SGT tag rides inside the VXLAN Group Policy Option header.
⚠ Common exam trap
350-401 often tests the misconception that the underlay must be SGT-aware or that the border node enforces all intra-fabric policy, when in fact SGTs are carried in the VXLAN overlay and enforcement occurs at the fabric edge.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy enforcement in SD-Access is based on Scalable Group Tags (SGTs) assigned to endpoints.
Option A is correct because SD-Access group-based policy enforcement relies on Scalable Group Tags (SGTs) that are assigned to endpoints (statically or dynamically via Cisco ISE), and these tags are the basis for permitting or denying traffic between groups rather than relying solely on IP addresses. Option B is correct because Cisco Identity Services Engine (ISE) is the policy controller in SD-Access: it defines SGTs, maintains the SGT-to-policy mappings (group-based access control contracts), and distributes that policy information to the fabric control plane nodes. Option D is correct because in the SD-Access VXLAN data plane the SGT is carried in the VXLAN-GPO (Group Policy Option) header field, allowing the egress fabric edge node to enforce policy based on the source group tag without the underlay needing to inspect the packet. Option C is not correct because intra-fabric policy enforcement between endpoints in different virtual networks is performed by the fabric edge nodes (with the SGT carried in VXLAN-GPO), not by the border node, which primarily handles external connectivity and VRF-aware handoff. Option E is not correct because the underlay network only provides IP reachability between fabric nodes; it does not need to be aware of SGTs, since SGT-based policy is enforced at the fabric edge in the overlay.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Policy enforcement in SD-Access is based on Scalable Group Tags (SGTs) assigned to endpoints.
Why this is correct
SD-Access enforces group-based policy using SGTs applied to endpoints, rather than traditional IP-based ACLs. This satisfies the stem by naming the actual tagging mechanism that the fabric's policy plane relies on for segmentation and contract enforcement between scalable groups.
- ✓
Cisco ISE is used to define and manage SGT-to-policy mappings in the SD-Access fabric.
Why this is correct
Cisco ISE acts as the policy controller, defining and distributing SGT-to-policy mappings to fabric nodes via the Cisco Platform Exchange Grid. This satisfies the stem by identifying the specific management component that authors the group-based contracts enforced across the SD-Access fabric.
- ✗
The fabric border node enforces all intra-fabric policies between different virtual networks.
Why it's wrong here
Intra-VN policy is enforced at the fabric edge nodes where endpoints attach, not at the border, which handles external connectivity and VN handoff. It is tempting because the border does enforce inter-VN traffic, so it is the correct enforcement point for cross-virtual-network policy.
- ✓
The SGT information is carried in the VXLAN header using the Group Policy Option (GPO).
Why this is correct
SGT values are transported in the VXLAN Group Policy Option field of the header, allowing intermediate fabric nodes to enforce policy without inspecting the inner packet. This satisfies the stem by naming the exact encapsulation mechanism carrying group context across the SD-Access fabric.
- ✗
The underlay network devices must be aware of SGTs to forward traffic correctly.
Why it's wrong here
SGTs are carried in VXLAN-GPO headers and enforced by fabric edge and border nodes; underlay devices forward on IP reachability alone and never inspect tags. It is tempting because underlay transport must carry the encapsulated packets, but awareness of SGTs is not required for that forwarding.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco SD-Access
Cisco Software-Defined Access is a network architecture that uses a central controller to automate and secure user and device access across an enterprise network.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which three statements about Cisco SD-Access policy enforcement are true? (Choose three.)
hard- ✓ A.Scalable Group Tags (SGTs) are used to enforce micro-segmentation and policy in the fabric.
- B.SGTs are assigned to endpoints based on their IP address only.
- C.The fabric border node enforces all policies for traffic within the fabric.
- ✓ D.Cisco ISE is used to define and manage policy in SD-Access.
- ✓ E.The fabric edge node applies policy based on SGTs in the VXLAN header.
Why A: Option A is correct because Scalable Group Tags (SGTs) are the fundamental mechanism for micro-segmentation in Cisco SD-Access, allowing group-based policy enforcement rather than traditional IP-based ACLs. Option D is correct because Cisco Identity Services Engine (ISE) serves as the policy plane in SD-Access, defining and managing group-based policies, SGT assignments, and TrustSec matrix rules. Option E is correct because the fabric edge node enforces policy by inspecting the SGT carried in the VXLAN-GPO header (Group Policy Option) of encapsulated traffic, applying the appropriate SGACL or contract. Option B is incorrect because SGTs can be assigned dynamically via ISE using 802.1X, MAC authentication bypass, or static mapping, not based on IP address alone. Option C is incorrect because policy enforcement in SD-Access occurs primarily at the fabric edge nodes (and fabric border for external traffic), not exclusively at the border node for all intra-fabric traffic.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.