mediumMultiple Select
350-401 Practice Question: Which two statements about SD-WAN architecture…
Which two statements about SD-WAN architecture are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the role separation between vBond, vSmart, and vManage, so candidates confuse the orchestrator (vBond) with the controller (vSmart) and incorrectly assume vBond forwards data or that vEdges peer with each other via OMP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vSmart controller is responsible for distributing routing and policy information to the WAN edge routers.
Option A is correct because in Cisco SD-WAN the vSmart controller is the centralized control plane component that distributes OMP routing information and policy (centralized and application-aware routing policies) to the WAN edge devices. Option B is correct because vEdge routers build the data plane themselves: they establish IPsec (and where applicable GRE) tunnels directly between edge devices, with the vSmart/vBond only facilitating control and orchestration, not carrying the payload traffic. Option C is wrong because the vBond orchestrator only performs initial authentication and NAT traversal/orchestration, helping edges find each other and the vSmart controllers; it does not forward data traffic. Option D is wrong because OMP sessions are formed between each vEdge and the vSmart controller (over DTLS/TLS), not between vEdge routers themselves. Option E is wrong because control plane communication between vSmart and vEdge uses DTLS/TLS (with OMP running over it), not IPsec, which is used for the data plane tunnels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The vSmart controller is responsible for distributing routing and policy information to the WAN edge routers.
Why this is correct
The vSmart controller runs the control plane, computing and distributing OMP routing and policy information to WAN edge routers, which then make forwarding decisions. This satisfies the statement describing vSmart's role in propagating routes and policies.
- ✓
vEdge routers establish IPsec tunnels directly with each other for data plane traffic.
Why this is correct
In Cisco SD-WAN, the data plane uses IPsec tunnels built directly between vEdge (WAN edge) routers, carrying traffic without transiting the controllers. This satisfies the statement that edge routers form tunnels with each other for data forwarding.
- ✗
The vBond orchestrator is responsible for forwarding data traffic between branch sites.
Why it's wrong here
The vBond orchestrator handles initial authentication and NAT traversal, coordinating vEdge and vSmart bring-up; it never carries data-plane traffic, which flows directly between vEdge routers over IPsec tunnels. It is tempting because vBond is the first contact point for every device joining the overlay.
- ✗
vEdge routers establish OMP sessions with each other to exchange control plane information.
Why it's wrong here
OMP sessions are formed between vEdge routers and vSmart controllers, not directly between vEdge devices; vEdges learn routes from vSmarts over OMP and never peer with each other. It is tempting because OMP does distribute control-plane routing information across the overlay, which is the fabric's actual function.
- ✗
Control plane communication between vSmart and vEdge is secured using IPsec.
Why it's wrong here
vSmart-to-vEdge OMP sessions run over DTLS, not IPsec; IPsec secures the data-plane tunnels between vEdge routers. It is tempting because IPsec is the fabric's headline encryption mechanism, but it protects transport traffic rather than the control plane.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Network Architecture Fundamentals
Key term
GRE
GRE (Generic Routing Encapsulation) is a tunneling protocol that encapsulates packets inside other packets to transport them across incompatible networks.
Key term
Cisco SD-WAN
Cisco SD-WAN is a software-defined wide area network architecture that separates the control and data planes to centrally manage and optimize traffic across multiple WAN connections.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.