Courseiva
mediumMultiple Choice

350-401 Practice Question: Is deploying a Cisco SD-WAN solution for a global…

A network engineer is deploying a Cisco SD-WAN solution for a global enterprise with multiple regional hubs. The engineer wants to ensure that traffic from branch offices to the internet is always forwarded directly from the branch, even if the branch has a primary MPLS link and a backup broadband link. The engineer configures the vSmart policy to direct internet-bound traffic to use the local exit at the branch. However, after deployment, the engineer notices that some internet traffic is still being sent to the regional hub before reaching the internet. What is the most likely cause of this behavior?

⚠ Common exam trap

Cisco often tests the distinction between VPN 0 and service VPNs in SD-WAN policy application, trapping candidates who assume any data policy applied globally will affect all traffic, when in fact the VPN context determines which traffic the policy matches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The engineer configured the data policy under VPN 0 instead of the service VPN (e.g., VPN 10).

In Cisco SD-WAN, data policies that control traffic forwarding (such as forcing local internet exit) must be applied to the service VPN (e.g., VPN 10) where the branch’s LAN and internet-bound traffic resides. Configuring the policy under VPN 0 (the transport VPN) only affects overlay tunnel traffic and control-plane packets, not user traffic. Since the engineer applied the policy to VPN 0, the policy did not match internet-bound traffic in the service VPN, causing it to follow the default route toward the regional hub.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The engineer configured the data policy under VPN 0 instead of the service VPN (e.g., VPN 10).

    Why this is correct

    In Cisco SD-WAN, data policy is applied per VPN and direction. Placing the policy under VPN 0 (the transport VPN) means it only inspects traffic entering or leaving the transport interface, not the service-side traffic from the LAN. Internet-bound traffic from the service VPN (e.g., VPN 10) must be matched by a data policy configured under that specific service VPN. Because the policy was placed in VPN 0, it never matched the LAN traffic, so the local exit was not enforced and the traffic continued toward the hub.

  • ✗

    The branch router does not have a default route in its routing table for the service VPN.

    Why it's wrong here

    A missing default route in the service VPN routing table would cause traffic to be dropped at the branch router, not forwarded to the hub. If no route (including a default route via OMP) exists, the router would send an ICMP unreachable or simply discard the packets. Since the symptom is that traffic is forwarding to the hub, a valid route (likely a default route learned via OMP from the hub) must exist. Therefore, this cannot be the root cause of the internet traffic not taking local exit.

  • ✗

    The engineer used a localized data policy instead of a centralized data policy.

    Why it's wrong here

    A localized data policy can absolutely enforce local exit if it is applied correctly on the service VPN. In contrast to centralized policies, localized policies are configured directly on the device, but they can still match traffic and set the local next-hop or direct it to the local Internet gateway. The problem in this scenario is not the policy type, but that the policy was attached to the wrong VPN. Thus, choosing a localized policy does not inherently prevent local exit.

  • ✗

    The OMP route redistribution is not enabled on the branch router.

    Why it's wrong here

    OMP route redistribution controls how LAN prefixes are advertised into the overlay and how overlay routes are learned, which affects site-to-site connectivity. Internet traffic destined for a local Internet exit does not depend on OMP redistribution; the routing decision is made by the data policy that steers traffic to the local gateway. If OMP were not enabled, the branch would simply not exchange overlay routes with the hub, but that would not send internet traffic to the hub as an unintended behavior. The core issue remains the incorrect placement of the data policy, not OMP.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.