Courseiva
mediumMultiple Choice

350-401 Practice Question: An architect is designing an SD-Access fabric for…

An architect is designing an SD-Access fabric for a large campus network. The design must support wireless clients that roam across different access switches without requiring a centralized wireless LAN controller. Which fabric component and protocol combination should the architect use to enable this mobility?

⚠ Common exam trap

Cisco often tests the misconception that SD-Access requires a centralized WLC for wireless roaming, but the trap here is that fabric mode APs offload mobility to the fabric edge switches using VXLAN/LISP, eliminating the need for a WLC controller.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fabric edge switches with VXLAN and LISP; APs in fabric mode (SD-Access enabled).

SD-Access fabric uses fabric edge switches with VXLAN (data plane) and LISP (control plane) to create a distributed overlay that supports seamless wireless client roaming. APs in fabric mode (SD-Access enabled) integrate directly with the fabric, allowing the fabric edge to handle mobility without a centralized WLC, as the client's context is maintained across the VXLAN overlay.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fabric edge switches with VXLAN and LISP; APs in local mode with a centralized WLC.

    Why it's wrong here

    Local mode APs terminate CAPWAP data tunnels on a centralized WLC, so even though the wired side uses fabric edge switches, all wireless client traffic must hairpin through the WLC rather than entering the VXLAN fabric at the access edge. Because the wireless data plane bypasses the fabric edge, LISP cannot register or track those wireless endpoints for mobility and policy enforcement. This reintroduces the scale and convergence problem SD-Access is designed to eliminate.

  • ✓

    Fabric edge switches with VXLAN and LISP; APs in fabric mode (SD-Access enabled).

    Why this is correct

    In SD-Access wireless, the CAPWAP control plane terminates on the fabric WLC, but the AP's data plane terminates locally on the fabric edge switch, which uses VXLAN to carry the wireless client traffic across the fabric. The wireless client is registered as a LISP EID with the fabric control plane, enabling seamless roaming between APs without changing the client's IP address. Only this fabric-mode AP design preserves the distributed anycast gateway and micro-segmentation for wireless endpoints.

  • ✗

    Fabric border nodes with VXLAN and LISP; APs in flexconnect mode with a local switch.

    Why it's wrong here

    Fabric border nodes are north-south connection points between the SD-Access fabric and external networks, not the access-layer infrastructure where APs and wireless clients connect, so placing APs there misidentifies the role and traffic flow. FlexConnect mode allows local switching at the AP but still relies on a WLC for control, and it lacks native VXLAN/LISP attachment to the fabric; the AP would need to be a fabric AP mapped to a fabric edge for wireless clients to receive fabric policies. Thus this mixed design neither provides fabric integration nor avoids a control-plane dependency.

  • ✗

    Fabric control plane nodes with VXLAN and LISP; APs in monitor mode.

    Why it's wrong here

    Fabric control plane nodes run the LISP mapping system, storing and serving endpoint-to-decapsulator mappings, and they do not forward wireless user data, so they cannot act as the physical attachment point for APs. Monitor-mode APs scan radios and send captured packets to a WLC for security analysis; since they do not pass client traffic or associate clients, they cannot provide wireless connectivity or support roaming. Combining these two unrelated roles leaves no forwarding path for wireless clients and fails to deploy a fabric edge at the access layer.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.