Courseiva
mediumMultiple Select

350-401 Practice Question: Which two statements about SD-WAN architecture…

Which two statements about SD-WAN architecture are true? (Choose two.)

⚠ Common exam trap

350-401 often tests the role separation between vBond, vSmart, and vManage, so candidates confuse the orchestrator (vBond) with the controller (vSmart) and incorrectly assume vBond forwards data or that vEdges peer with each other via OMP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The vSmart controller is responsible for distributing routing and policy information to the WAN edge routers.

Option A is correct because in Cisco SD-WAN the vSmart controller is the centralized control plane component that distributes OMP routing information and policy (centralized and application-aware routing policies) to the WAN edge devices. Option B is correct because vEdge routers build the data plane themselves: they establish IPsec (and where applicable GRE) tunnels directly between edge devices, with the vSmart/vBond only facilitating control and orchestration, not carrying the payload traffic. Option C is wrong because the vBond orchestrator only performs initial authentication and NAT traversal/orchestration, helping edges find each other and the vSmart controllers; it does not forward data traffic. Option D is wrong because OMP sessions are formed between each vEdge and the vSmart controller (over DTLS/TLS), not between vEdge routers themselves. Option E is wrong because control plane communication between vSmart and vEdge uses DTLS/TLS (with OMP running over it), not IPsec, which is used for the data plane tunnels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The vSmart controller is responsible for distributing routing and policy information to the WAN edge routers.

    Why this is correct

    The vSmart controller runs the control plane, computing and distributing OMP routing and policy information to WAN edge routers, which then make forwarding decisions. This satisfies the statement describing vSmart's role in propagating routes and policies.

  • ✓

    vEdge routers establish IPsec tunnels directly with each other for data plane traffic.

    Why this is correct

    In Cisco SD-WAN, the data plane uses IPsec tunnels built directly between vEdge (WAN edge) routers, carrying traffic without transiting the controllers. This satisfies the statement that edge routers form tunnels with each other for data forwarding.

  • ✗

    The vBond orchestrator is responsible for forwarding data traffic between branch sites.

    Why it's wrong here

    The vBond orchestrator handles initial authentication and NAT traversal, coordinating vEdge and vSmart bring-up; it never carries data-plane traffic, which flows directly between vEdge routers over IPsec tunnels. It is tempting because vBond is the first contact point for every device joining the overlay.

  • ✗

    vEdge routers establish OMP sessions with each other to exchange control plane information.

    Why it's wrong here

    OMP sessions are formed between vEdge routers and vSmart controllers, not directly between vEdge devices; vEdges learn routes from vSmarts over OMP and never peer with each other. It is tempting because OMP does distribute control-plane routing information across the overlay, which is the fabric's actual function.

  • ✗

    Control plane communication between vSmart and vEdge is secured using IPsec.

    Why it's wrong here

    vSmart-to-vEdge OMP sessions run over DTLS, not IPsec; IPsec secures the data-plane tunnels between vEdge routers. It is tempting because IPsec is the fabric's headline encryption mechanism, but it protects transport traffic rather than the control plane.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.