Topic 03 Practice Test 1 covers Cisco SD-Access Architecture and Traditional Campus Interoperation for Cisco 350-401 ENCOR. For broader exam preparation, review the Cisco 350-401 ENCOR Exam Dumps. Every option includes focused technical reasoning explaining both the Cisco enterprise networking concept and its fit to the scenario.
Question 1
During an ENCOR architecture review, engineers need to attach user endpoints to the fabric and register their endpoint identities with the control plane. Which SD-Access component or mechanism is the best fit? Choose ONE.
- fabric edge node
- control-plane node
- intermediate node
- border node
Correct Answer(s)
A
Rationale
- Use fabric edge node. The fabric edge is the endpoint-facing xTR: it provides the fabric attachment, maps endpoint identity to its routing locator, and originates the registration used by the LISP control plane. The requirement is to attach user endpoints to the fabric and register their endpoint identities with the control plane. This places the requirement on the component that actually owns the needed behavior in the fabric design.
- control-plane node handles a different function: maintains LISP mapping information and answers endpoint-location queries rather than serving as the user data path. The requirement here is to attach user endpoints to the fabric and register their endpoint identities with the control plane. Selecting it would blur role boundaries without delivering the specific result required by the question.
- intermediate node handles a different function: provides routed underlay transport and does not perform the endpoint-facing overlay role. The requirement here is to attach user endpoints to the fabric and register their endpoint identities with the control plane. The feature addresses a neighboring concern, leaving the actual requirement unresolved.
- border node handles a different function: connects the fabric to external routed domains and is not the normal endpoint attachment role. The requirement here is to attach user endpoints to the fabric and register their endpoint identities with the control plane. The choice is valid technology, but it cannot own the responsibility identified by the scenario.
Question 2
A design assurance review asks how to provide the authoritative endpoint-ID-to-routing-locator directory used by fabric nodes. Which fabric element or behavior should be selected? Choose ONE.
- border node
- fabric edge node
- control-plane node
- intermediate node
Correct Answer(s)
C
Rationale
- border node handles a different function: connects the fabric to external routed domains and is not the normal endpoint attachment role. The requirement here is to provide the authoritative endpoint-ID-to-routing-locator directory used by fabric nodes. The mechanism is useful for another task, but this evidence points to a different fabric responsibility.
- fabric edge node handles a different function: attaches endpoints, provides the fabric first hop, and participates in overlay endpoint reachability. The requirement here is to provide the authoritative endpoint-ID-to-routing-locator directory used by fabric nodes. This distinction prevents a valid fabric feature from being mistaken for the component required here.
- Use control-plane node. The control-plane node hosts the LISP map-server/map-resolver functions and maintains the host-tracking database used for endpoint-location lookups. The requirement is to provide the authoritative endpoint-ID-to-routing-locator directory used by fabric nodes. This mechanism owns the relevant function, so it addresses the design evidence more precisely than the neighboring choices.
- intermediate node handles a different function: provides routed underlay transport and does not perform the endpoint-facing overlay role. The requirement here is to provide the authoritative endpoint-ID-to-routing-locator directory used by fabric nodes. Its normal operation targets another concern and therefore does not complete the required design action.
Question 3
The implementation team is mapping a requirement to an SD-Access role: carry user overlay traffic between fabric nodes after endpoint location has been resolved. Which option is the correct mapping? Choose ONE.
- Cisco ISE policy service
- VXLAN data plane
- LISP control plane
- Catalyst Center management plane
Correct Answer(s)
B
Rationale
- Cisco ISE policy service handles a different function: supplies identity and group-policy services rather than carrying overlay data traffic. The requirement here is to carry user overlay traffic between fabric nodes after endpoint location has been resolved. The design would still need the proper function even if this option were already deployed.
- Use VXLAN data plane. SD-Access uses VXLAN encapsulation for the overlay data plane so traffic can cross the routed underlay while preserving virtual-network context. The requirement is to carry user overlay traffic between fabric nodes after endpoint location has been resolved. Selecting this function follows Cisco SD-Access role separation and addresses the condition identified in the design review.
- LISP control plane handles a different function: resolves endpoint identity-to-location information instead of transporting user payloads. The requirement here is to carry user overlay traffic between fabric nodes after endpoint location has been resolved. The scenario depends on another responsibility, so this choice cannot satisfy the stated outcome.
- Catalyst Center management plane handles a different function: orchestrates and automates the fabric instead of being the per-packet overlay transport. The requirement here is to carry user overlay traffic between fabric nodes after endpoint location has been resolved. The requirement calls for a different function, so this mechanism is not an equivalent substitute.
Question 4
A brownfield design has one controlling requirement: give hosts the same default-gateway address and MAC behavior as they move between fabric edge nodes. What should the architect select? Choose ONE.
- intermediate-node underlay routing
- control-plane map resolver
- border-node BGP handoff
- fabric edge anycast gateway
Correct Answer(s)
D
Rationale
- intermediate-node underlay routing handles a different function: moves infrastructure IP traffic between nodes without acting as the endpoint gateway. The requirement here is to give hosts the same default-gateway address and MAC behavior as they move between fabric edge nodes. The option therefore fails the functional mapping established by the evidence in the scenario.
- control-plane map resolver handles a different function: answers mapping queries but is not an endpoint default gateway. The requirement here is to give hosts the same default-gateway address and MAC behavior as they move between fabric edge nodes. The stated outcome remains unmet because this mechanism performs a separate job in the fabric.
- border-node BGP handoff handles a different function: exchanges routed reachability at the fabric boundary rather than providing the endpoint first hop. The requirement here is to give hosts the same default-gateway address and MAC behavior as they move between fabric edge nodes. The mismatch places the option at the wrong architectural responsibility for this decision.
- Use fabric edge anycast gateway. An anycast gateway on fabric edges presents a consistent first-hop gateway to endpoints while the fabric tracks their actual attachment point. The requirement is to give hosts the same default-gateway address and MAC behavior as they move between fabric edge nodes. The selection therefore follows the intended separation of duties among SD-Access nodes, planes, and boundaries.
Question 5
Before approving the campus architecture, the team must ensure it can forward only underlay IP traffic between fabric nodes without terminating the overlay. Which option is technically correct? Choose ONE.
- fabric edge node
- border node
- intermediate node
- control-plane node
Correct Answer(s)
C
Rationale
- fabric edge node handles a different function: attaches endpoints, provides the fabric first hop, and participates in overlay endpoint reachability. The requirement here is to forward only underlay IP traffic between fabric nodes without terminating the overlay. The option belongs elsewhere in the design and does not provide the behavior the stem asks for.
- border node handles a different function: connects the fabric to external routed domains and is not the normal endpoint attachment role. The requirement here is to forward only underlay IP traffic between fabric nodes without terminating the overlay. Its normal operation targets another concern and therefore does not complete the required design action.
- Use intermediate node. Intermediate nodes supply routed IP reachability through the underlay; they do not need to act as LISP control-plane nodes or VXLAN tunnel endpoints for attached users. The requirement is to forward only underlay IP traffic between fabric nodes without terminating the overlay. This mechanism owns the relevant function, so it addresses the design evidence more precisely than the neighboring choices.
- control-plane node handles a different function: maintains LISP mapping information and answers endpoint-location queries rather than serving as the user data path. The requirement here is to forward only underlay IP traffic between fabric nodes without terminating the overlay. It can coexist in the solution, but it does not solve the condition described here.
Question 6
A design change is proposed so the network can provide the Layer 3 gateway between the SD-Access fabric and an external enterprise network. Which SD-Access function most directly enables it? Choose ONE.
- control-plane node
- fabric edge node
- border node
- intermediate node
Correct Answer(s)
C
Rationale
- control-plane node handles a different function: maintains LISP mapping information and answers endpoint-location queries rather than serving as the user data path. The requirement here is to provide the Layer 3 gateway between the SD-Access fabric and an external enterprise network. The design would still need the proper function even if this option were already deployed.
- fabric edge node handles a different function: attaches endpoints, provides the fabric first hop, and participates in overlay endpoint reachability. The requirement here is to provide the Layer 3 gateway between the SD-Access fabric and an external enterprise network. The fabric still needs the correct component for the requested behavior, making this option insufficient.
- Use border node. A border node terminates the fabric overlay for north-south connectivity and exchanges reachability with networks outside the fabric. The requirement is to provide the Layer 3 gateway between the SD-Access fabric and an external enterprise network. Selecting this function follows Cisco SD-Access role separation and addresses the condition identified in the design review.
- intermediate node handles a different function: provides routed underlay transport and does not perform the endpoint-facing overlay role. The requirement here is to provide the Layer 3 gateway between the SD-Access fabric and an external enterprise network. That role separation makes this technically plausible option incorrect for the decision being tested.
Question 7
Operations is validating an SD-Access deployment and must store current endpoint identifier to routing-locator mappings for control-plane lookups. Which option directly addresses that need? Choose ONE.
- BGP local RIB on an intermediate node
- Catalyst Center site hierarchy
- Cisco ISE endpoint profiling database
- host tracking database (HTDB)
Correct Answer(s)
D
Rationale
- BGP local RIB on an intermediate node handles a different function: contains routing state for conventional IP forwarding, not the fabric endpoint mapping database. The requirement here is to store current endpoint identifier to routing-locator mappings for control-plane lookups. This option operates on a different concern and cannot replace the function demanded by the scenario.
- Catalyst Center site hierarchy handles a different function: organizes management intent and site structure, not real-time EID-to-RLOC mappings. The requirement here is to store current endpoint identifier to routing-locator mappings for control-plane lookups. That architectural separation is why the option should be rejected for this particular case.
- Cisco ISE endpoint profiling database handles a different function: supports identity and profiling policy rather than LISP location resolution. The requirement here is to store current endpoint identifier to routing-locator mappings for control-plane lookups. This would solve the wrong layer of the problem and leave the controlling condition unchanged.
- Use host tracking database (HTDB). The control-plane function keeps endpoint reachability in the HTDB so map requests can resolve where an endpoint is currently attached. The requirement is to store current endpoint identifier to routing-locator mappings for control-plane lookups. The evidence points to this function specifically, rather than to a related mechanism elsewhere in the architecture.
Question 8
A Cisco SD-Access implementation has to advertise a newly learned endpoint location from a fabric edge toward the control-plane service. Which component provides that function? Choose ONE.
- BGP UPDATE to an external peer
- LISP Map-Register
- SNMP trap
- VXLAN encapsulation
Correct Answer(s)
B
Rationale
- BGP UPDATE to an external peer handles a different function: advertises IP routing information to a routing neighbor, not a fabric endpoint mapping to the LISP map server. The requirement here is to advertise a newly learned endpoint location from a fabric edge toward the control-plane service. Selecting it would blur role boundaries without delivering the specific result required by the question.
- Use LISP Map-Register. An edge xTR uses LISP registration to tell the control-plane map server about the endpoint identifier and the edge routing locator that currently owns it. The requirement is to advertise a newly learned endpoint location from a fabric edge toward the control-plane service. The scenario is resolved by the component responsible for this behavior, not by another feature that merely supports it.
- SNMP trap handles a different function: reports a management event and does not register an endpoint mapping. The requirement here is to advertise a newly learned endpoint location from a fabric edge toward the control-plane service. The feature addresses a neighboring concern, leaving the actual requirement unresolved.
- VXLAN encapsulation handles a different function: provide the function described by VXLAN encapsulation. The requirement here is to advertise a newly learned endpoint location from a fabric edge toward the control-plane service. The choice is valid technology, but it cannot own the responsibility identified by the scenario.
Question 9
A campus modernization review asks the architect to resolve the destination routing locator before sending overlay traffic to a remote endpoint. Which technology or node role should be selected? Choose ONE.
- LISP Map-Request and Map-Reply
- STP BPDU exchange
- BGP route reflection
- RADIUS Access-Request
Correct Answer(s)
A
Rationale
- Use LISP Map-Request and Map-Reply. A requesting xTR queries the mapping system for the destination EID; the returned mapping supplies the remote locator needed for the VXLAN forwarding decision. The requirement is to resolve the destination routing locator before sending overlay traffic to a remote endpoint. That functional mapping keeps the architecture clean and matches the evidence without borrowing another plane’s job.
- STP BPDU exchange handles a different function: controls Layer 2 loop prevention and does not resolve fabric endpoint locations. The requirement here is to resolve the destination routing locator before sending overlay traffic to a remote endpoint. That difference makes the feature relevant background technology rather than the answer to this requirement.
- BGP route reflection handles a different function: distributes BGP routes and is not the fabric EID mapping query process. The requirement here is to resolve the destination routing locator before sending overlay traffic to a remote endpoint. The mechanism is useful for another task, but this evidence points to a different fabric responsibility.
- RADIUS Access-Request handles a different function: performs authentication/authorization exchange rather than an overlay locator lookup. The requirement here is to resolve the destination routing locator before sending overlay traffic to a remote endpoint. This distinction prevents a valid fabric feature from being mistaken for the component required here.
Question 10
An enterprise fabric design is being corrected before rollout. The design must isolate two business groups at Layer 3 even when they use the same physical fabric. Which answer is most appropriate? Choose ONE.
- spanning-tree instance
- common access VLAN only
- single shared global routing table
- virtual network mapped to a VRF
Correct Answer(s)
D
Rationale
- spanning-tree instance handles a different function: controls Layer 2 topology and cannot substitute for a routed virtual-network context. The requirement here is to isolate two business groups at Layer 3 even when they use the same physical fabric. This option operates on a different concern and cannot replace the function demanded by the scenario.
- common access VLAN only handles a different function: creates a Layer 2 segment but does not independently isolate Layer 3 routing domains. The requirement here is to isolate two business groups at Layer 3 even when they use the same physical fabric. The scenario depends on another responsibility, so this choice cannot satisfy the stated outcome.
- single shared global routing table handles a different function: combines routes into one context and therefore does not preserve Layer 3 macro-segmentation. The requirement here is to isolate two business groups at Layer 3 even when they use the same physical fabric. This is an adjacent capability, not the architectural function that the scenario requires.
- Use virtual network mapped to a VRF. A virtual network is represented with separate routing context, commonly a VRF, so routes from one macro-segment are not automatically visible in another. The requirement is to isolate two business groups at Layer 3 even when they use the same physical fabric. This is the role whose native behavior fulfills the requirement without forcing another component into the wrong responsibility.
Question 11
The enterprise architecture standard requires the fabric to carry identity-based group context so policy can be enforced without depending only on IP subnets. Which selection aligns with that requirement? Choose ONE.
- security group tag (SGT)
- native VLAN number
- OSPF area ID
- VXLAN VNI alone
Correct Answer(s)
A
Rationale
- Use security group tag (SGT). SGTs express group identity separately from addressing, allowing group-based policy decisions to follow users or devices across the fabric. The requirement is to carry identity-based group context so policy can be enforced without depending only on IP subnets. The scenario is resolved by the component responsible for this behavior, not by another feature that merely supports it.
- native VLAN number handles a different function: identifies untagged Layer 2 treatment rather than user or device security-group identity. The requirement here is to carry identity-based group context so policy can be enforced without depending only on IP subnets. The mismatch places the option at the wrong architectural responsibility for this decision.
- OSPF area ID handles a different function: scopes link-state flooding and is unrelated to endpoint identity-group policy. The requirement here is to carry identity-based group context so policy can be enforced without depending only on IP subnets. The stated outcome remains unmet because this mechanism performs a separate job in the fabric.
- VXLAN VNI alone handles a different function: identifies an overlay segment but is not itself an identity-based policy label. The requirement here is to carry identity-based group context so policy can be enforced without depending only on IP subnets. The feature addresses a neighboring concern, leaving the actual requirement unresolved.
Question 12
A fabric validation exercise identifies this requirement: automate fabric provisioning, site design, device roles, and policy deployment from a centralized controller. Which answer matches the required function? Choose ONE.
- Cisco ISE
- Catalyst Center
- border-node BGP process
- LISP map server
Correct Answer(s)
B
Rationale
- Cisco ISE handles a different function: provides identity, authentication, and group-policy services rather than the primary fabric provisioning workflow. The requirement here is to automate fabric provisioning, site design, device roles, and policy deployment from a centralized controller. The mechanism is useful for another task, but this evidence points to a different fabric responsibility.
- Use Catalyst Center. Catalyst Center provides the SD-Access management and automation workflow that turns intent into coordinated fabric configuration. The requirement is to automate fabric provisioning, site design, device roles, and policy deployment from a centralized controller. The choice is therefore justified by the requirement itself, not simply by its presence elsewhere in an SD-Access deployment.
- border-node BGP process handles a different function: exchanges external routes, not the complete fabric management workflow. The requirement here is to automate fabric provisioning, site design, device roles, and policy deployment from a centralized controller. Its normal operation targets another concern and therefore does not complete the required design action.
- LISP map server handles a different function: maintains endpoint mappings and does not replace centralized lifecycle orchestration. The requirement here is to automate fabric provisioning, site design, device roles, and policy deployment from a centralized controller. Its presence would not remove the need for the mechanism that owns the requested behavior.
Question 13
A network architect is comparing several SD-Access choices. The required outcome is to assign identity and group policy context based on users and endpoints for fabric access control. Which choice should be used? Choose ONE.
- Cisco ISE
- VXLAN tunnel endpoint
- underlay OSPF process
- Catalyst Center inventory only
Correct Answer(s)
A
Rationale
- Use Cisco ISE. ISE supplies identity services and TrustSec policy information used to classify endpoints and support group-based access decisions. The requirement is to assign identity and group policy context based on users and endpoints for fabric access control. This is the role whose native behavior fulfills the requirement without forcing another component into the wrong responsibility.
- VXLAN tunnel endpoint handles a different function: terminates overlay tunnels but does not authenticate users or assign enterprise identity policy. The requirement here is to assign identity and group policy context based on users and endpoints for fabric access control. The design would still need the proper function even if this option were already deployed.
- underlay OSPF process handles a different function: provides infrastructure reachability and does not determine endpoint identity or group authorization. The requirement here is to assign identity and group policy context based on users and endpoints for fabric access control. The scenario depends on another responsibility, so this choice cannot satisfy the stated outcome.
- Catalyst Center inventory only handles a different function: tracks managed infrastructure but identity-based group policy requires the policy service as well. The requirement here is to assign identity and group policy context based on users and endpoints for fabric access control. It does not provide the needed outcome at the relevant boundary, so the design requirement remains open.
Question 14
During a phased campus transformation, engineers must provide reliable IP reachability among fabric routing locators before overlay services are built. Which design choice best preserves the intended architecture? Choose ONE.
- single Layer 2 campus domain
- endpoint-only static routing
- Layer 3 routed underlay
- stretched access VLAN underlay
Correct Answer(s)
C
Rationale
- single Layer 2 campus domain handles a different function: depends on bridging rather than the scalable routed underlay required by the fabric. The requirement here is to provide reliable IP reachability among fabric routing locators before overlay services are built. This would solve the wrong layer of the problem and leave the controlling condition unchanged.
- endpoint-only static routing handles a different function: does not provide a scalable infrastructure transport for all fabric node locators. The requirement here is to provide reliable IP reachability among fabric routing locators before overlay services are built. The stated outcome remains unmet because this mechanism performs a separate job in the fabric.
- Use Layer 3 routed underlay. The fabric overlay depends on ordinary routed IP connectivity between node loopbacks and infrastructure addresses; endpoint subnets belong in the overlay rather than the underlay. The requirement is to provide reliable IP reachability among fabric routing locators before overlay services are built. The scenario is resolved by the component responsible for this behavior, not by another feature that merely supports it.
- stretched access VLAN underlay handles a different function: extends Layer 2 failure domains and does not provide the intended routed transport foundation. The requirement here is to provide reliable IP reachability among fabric routing locators before overlay services are built. Using it here would assign the problem to the wrong node role or fabric plane.
Question 15
An SD-Access solution must preserve a specific design property: represent the endpoint address whose current network location may change. Which option should be implemented? Choose ONE.
- routing locator (RLOC)
- VXLAN VNI
- endpoint identifier (EID)
- BGP autonomous-system number
Correct Answer(s)
C
Rationale
- routing locator (RLOC) handles a different function: identifies a topological fabric-node location reachable through the underlay. The requirement here is to represent the endpoint address whose current network location may change. Its presence would not remove the need for the mechanism that owns the requested behavior.
- VXLAN VNI handles a different function: identifies overlay forwarding context and is not the endpoint address itself. The requirement here is to represent the endpoint address whose current network location may change. The choice is valid technology, but it cannot own the responsibility identified by the scenario.
- Use endpoint identifier (EID). LISP separates endpoint identity from topology location: the EID names the endpoint, while the RLOC identifies the fabric node location used to reach it. The requirement is to represent the endpoint address whose current network location may change. That functional mapping keeps the architecture clean and matches the evidence without borrowing another plane’s job.
- BGP autonomous-system number handles a different function: identifies a BGP routing domain and is neither endpoint identity nor locator. The requirement here is to represent the endpoint address whose current network location may change. It can coexist in the solution, but it does not solve the condition described here.
Question 16
While troubleshooting a fabric design, the team confirms that it needs to identify the routable fabric-node location used as the tunnel destination for an endpoint mapping. Which mechanism belongs in that role? Choose ONE.
- routing locator (RLOC)
- endpoint identifier (EID)
- security group tag (SGT)
- user VLAN name
Correct Answer(s)
A
Rationale
- Use routing locator (RLOC). The RLOC is topological and reachable through the underlay; it points to the fabric node that currently provides reachability for the EID. The requirement is to identify the routable fabric-node location used as the tunnel destination for an endpoint mapping. That assignment preserves clear fabric roles and delivers the behavior described by the scenario with no unnecessary substitution.
- endpoint identifier (EID) handles a different function: names an endpoint independently from the topological location of the fabric node serving it. The requirement here is to identify the routable fabric-node location used as the tunnel destination for an endpoint mapping. This distinction prevents a valid fabric feature from being mistaken for the component required here.
- security group tag (SGT) handles a different function: labels policy identity and is not a routable node locator. The requirement here is to identify the routable fabric-node location used as the tunnel destination for an endpoint mapping. That role separation makes this technically plausible option incorrect for the decision being tested.
- user VLAN name handles a different function: is administrative Layer 2 labeling, not the LISP topological locator. The requirement here is to identify the routable fabric-node location used as the tunnel destination for an endpoint mapping. That difference makes the feature relevant background technology rather than the answer to this requirement.
Question 17
A fabric readiness assessment focuses on one outcome: exchange summarized or coarse reachability between the fabric and an external routed domain. Which option provides that behavior? Choose ONE.
- LISP Map-Register from every endpoint
- BGP on the border node
- STP on the intermediate nodes
- VXLAN flooding to the external router
Correct Answer(s)
B
Rationale
- LISP Map-Register from every endpoint handles a different function: registers fabric endpoint location but does not replace external route exchange. The requirement here is to exchange summarized or coarse reachability between the fabric and an external routed domain. Using it here would assign the problem to the wrong node role or fabric plane.
- Use BGP on the border node. The border is the routing demarcation to external networks, and BGP is the normal mechanism for exchanging external reachability without turning endpoint mobility into underlay routing. The requirement is to exchange summarized or coarse reachability between the fabric and an external routed domain. This keeps transport, control, policy, and management responsibilities distinct while meeting the specific operational need.
- STP on the intermediate nodes handles a different function: controls Layer 2 loops and is not the fabric-to-external routing protocol. The requirement here is to exchange summarized or coarse reachability between the fabric and an external routed domain. The requirement calls for a different function, so this mechanism is not an equivalent substitute.
- VXLAN flooding to the external router handles a different function: would extend overlay behavior rather than use a proper routed external handoff. The requirement here is to exchange summarized or coarse reachability between the fabric and an external routed domain. This option operates on a different concern and cannot replace the function demanded by the scenario.
Question 18
A campus team is designing an SD-Access fabric. It must preserve Layer 2 adjacency for endpoints that belong to the same fabric VLAN segment. Which choice best satisfies the requirement? Choose ONE.
- BGP community
- Layer 3 VNI for a VRF
- LISP RLOC address
- Layer 2 VNI
Correct Answer(s)
D
Rationale
- BGP community handles a different function: is a routing-policy attribute and not an overlay segment identifier. The requirement here is to preserve Layer 2 adjacency for endpoints that belong to the same fabric VLAN segment. The mismatch places the option at the wrong architectural responsibility for this decision.
- Layer 3 VNI for a VRF handles a different function: identifies routed overlay context for a virtual network rather than a single Layer 2 segment. The requirement here is to preserve Layer 2 adjacency for endpoints that belong to the same fabric VLAN segment. The option therefore fails the functional mapping established by the evidence in the scenario.
- LISP RLOC address handles a different function: identifies a fabric-node locator, not a broadcast segment. The requirement here is to preserve Layer 2 adjacency for endpoints that belong to the same fabric VLAN segment. The feature addresses a neighboring concern, leaving the actual requirement unresolved.
- Use Layer 2 VNI. A Layer 2 VNI identifies a bridged overlay segment so Ethernet traffic can traverse the routed fabric between applicable edge nodes. The requirement is to preserve Layer 2 adjacency for endpoints that belong to the same fabric VLAN segment. That choice satisfies the stated outcome while preserving the normal responsibilities of the surrounding fabric components.
Question 19
A migration workshop identifies a non-negotiable requirement: identify routed virtual-network context when traffic crosses between Layer 3 overlay endpoints. Which SD-Access design choice meets it? Choose ONE.
- native VLAN tag
- OSPF router ID
- Layer 2 VNI only
- Layer 3 VNI
Correct Answer(s)
D
Rationale
- native VLAN tag handles a different function: controls untagged Ethernet behavior rather than routed overlay context. The requirement here is to identify routed virtual-network context when traffic crosses between Layer 3 overlay endpoints. The mechanism is useful for another task, but this evidence points to a different fabric responsibility.
- OSPF router ID handles a different function: identifies an OSPF speaker and has no role as a VXLAN routed VNI. The requirement here is to identify routed virtual-network context when traffic crosses between Layer 3 overlay endpoints. Its normal operation targets another concern and therefore does not complete the required design action.
- Layer 2 VNI only handles a different function: identifies a bridged segment and is insufficient for the stated routed virtual-network context. The requirement here is to identify routed virtual-network context when traffic crosses between Layer 3 overlay endpoints. That difference makes the feature relevant background technology rather than the answer to this requirement.
- Use Layer 3 VNI. A Layer 3 VNI represents the routed overlay context associated with a virtual network or VRF rather than a single bridged VLAN. The requirement is to identify routed virtual-network context when traffic crosses between Layer 3 overlay endpoints. This choice solves the controlling condition directly while adjacent fabric features continue performing their separate purposes.
Question 20
A production campus needs to combine fabric edge, control-plane, and border functions on one supported device for a small site. Which SD-Access mechanism should be chosen instead of an adjacent but different feature? Choose ONE.
- standalone external router with no fabric role
- fabric-in-a-box
- dedicated intermediate-only node
- Layer 2 access switch only
Correct Answer(s)
B
Rationale
- standalone external router with no fabric role handles a different function: can peer at a boundary but cannot provide the combined SD-Access node roles. The requirement here is to combine fabric edge, control-plane, and border functions on one supported device for a small site. The design would still need the proper function even if this option were already deployed.
- Use fabric-in-a-box. Fabric-in-a-Box collapses multiple SD-Access roles onto a single platform where scale and resiliency requirements permit, reducing the number of dedicated nodes. The requirement is to combine fabric edge, control-plane, and border functions on one supported device for a small site. This directly fulfills the scenario while maintaining the separation between endpoint, mapping, transport, and boundary functions.
- dedicated intermediate-only node handles a different function: provides transport only and cannot supply the combined endpoint, control, and border functions. The requirement here is to combine fabric edge, control-plane, and border functions on one supported device for a small site. The requirement calls for a different function, so this mechanism is not an equivalent substitute.
- Layer 2 access switch only handles a different function: does not implement the required fabric control, edge, and border capabilities. The requirement here is to combine fabric edge, control-plane, and border functions on one supported device for a small site. It does not provide the needed outcome at the relevant boundary, so the design requirement remains open.