easyMultiple Choice
Cisco SD-WAN Centralized Data Policy Troubleshooting
A network engineer is configuring a Cisco SD-WAN solution for a multinational corporation. The engineer wants to use a centralized data policy to steer all traffic from the Finance department (VPN 10) to a specific WAN link (MPLS) for security reasons. The engineer creates a policy that matches traffic from VPN 10 and sets the preferred color to 'mpls'. After applying the policy, the engineer tests and finds that traffic from VPN 10 is still using the Internet link. The vEdge routers show that the policy is received and active. What is the most likely reason?
⚠ Common exam trap
Cisco often tests the distinction between policy definition and policy attachment, where candidates assume that simply creating and applying a policy globally is sufficient, but the policy must be explicitly linked to the correct site list and VPN list to take effect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy is not attached to the correct site list or VPN list.
The most likely reason is that the centralized data policy was not attached to the correct site list or VPN list. In Cisco SD-WAN, a centralized data policy must be explicitly associated with the sites (via site list) and VPNs (via VPN list) where it should be applied. Even if the policy is received and active on the vEdge routers, without proper attachment to the VPN 10 site list, the policy will not enforce the preferred color 'mpls' for Finance traffic, leaving it to use the default Internet link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vEdge routers have not rebooted after the policy was applied.
Why it's wrong here
The vEdge routers do not need to be rebooted after a centralized data policy is applied. In Cisco SD-WAN, policy changes are propagated from vSmart to vEdge via OMP and take effect in the data plane immediately, without requiring a reboot or even a configuration reload. Therefore, the lack of reboot is not an explanation for why the policy is not being enforced.
- ✓
The policy is not attached to the correct site list or VPN list.
Why this is correct
A centralized data policy must be explicitly attached to a site list and a VPN list to define where it is enforced. If the policy is attached to the wrong site list (or wrong VPN list), vSmart may still distribute it, but the vEdge routers in the intended sites will never apply it to the relevant traffic. This is exactly the kind of configuration error that lets a policy appear present yet have no effect.
- ✗
The data policy was applied on the vEdge instead of the vSmart.
Why it's wrong here
In Cisco SD-WAN, centralized data policies are applied on the vSmart controller, which then distributes the policy to all vEdge routers through OMP. Since the engineer stated that the policy was applied on vSmart, this option is factually wrong—the policy is in the correct location. Applying the policy on the vEdge would be a localized data policy and would not match the described centralized deployment.
- ✗
The preferred color is not configured correctly in the policy.
Why it's wrong here
The preferred color is simply one of the actions or parameters inside the data policy; if it is configured but the policy is not attached to the right site list and VPN list, that action will never be executed. The engineer did set the preferred color correctly, but the 'no effect' symptom is caused by the missing attachment, not by a misconfigured color value. This option describes a policy parameter detail rather than the actual attachment issue.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.