Cisco CCNP Enterprise 350-401 ENCOR Catalyst SD-WAN and SD-Access Architecture Practice Test

 

Topic 02 covers catalyst sd-wan and sd-access architecture for the Cisco Certified Specialist – Enterprise Core certification. These original practice questions apply the verified 350-401 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the Cisco 350-401 ENCOR Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.

Question 1

A new Catalyst SD-WAN edge can reach its provider gateway, but it cannot complete the initial exchange that discovers the available management and control components. Existing sites continue forwarding. The configured orchestration address is unreachable from the new branch. Which component path should be investigated first?

  1. The service-side OSPF adjacency toward the branch LAN.
  2. The edge-to-remote-branch IPsec data path.
  3. The SD-WAN Manager web interface from an administrator laptop.
  4. The edge-to-SD-WAN Validator path.
  5. The application server path beyond a remote WAN edge.

Correct Answer: D

 

Correct Answer

Answer D is correct because the Validator coordinates initial control-component discovery and onboarding. Its configured address is the failing dependency identified before the new edge establishes normal controller relationships.

Incorrect Answers

Answer A is incorrect because LAN routes matter to subsequent route advertisement, whereas the evidence places the failure in discovering control components through the transport.

Answer B is incorrect because remote data tunnels are relevant after the edge obtains the required control information; they do not replace the failed initial orchestration exchange.

Answer C is incorrect because administrator access may help diagnosis, but its success does not establish reachability from the new edge to its configured orchestration endpoint.

Answer E is incorrect because an application server does not perform onboarding, and existing-site forwarding does not validate the new branch orchestration path.

 

Question 2

An edge advertises a new service prefix, but another branch does not learn it. Both edges retain established management sessions, and the WAN transport is reachable. The engineer must examine the component that receives OMP information and applies centralized route-distribution policy. Which investigation is appropriate?

  1. Change the remote application server default gateway first.
  2. Inspect only the Manager dashboard login permissions.
  3. Inspect the Validator as the permanent distributor of all service prefixes.
  4. Inspect the Internet provider as the source of the service VPN route.
  5. Inspect the relevant SD-WAN Controller OMP routes and control policy.

Correct Answer: E

 

Correct Answer

Answer E is correct because the Controller participates in OMP exchange and centralized control policy, making it the relevant point between an advertised service route and another branch learning that route.

Incorrect Answers

Answer A is incorrect because the stated failure is absence of the prefix in overlay control information, before application return-path behavior becomes the decisive issue.

Answer B is incorrect because administrator permissions can affect visibility but do not determine whether the Controller advertises the new service prefix.

Answer C is incorrect because the Validator assists orchestration; it does not replace the Controller OMP role after onboarding.

Answer D is incorrect because the provider supplies underlay reachability; it need not learn the enterprise service prefix transported by the overlay.

 

Question 3

Operators cannot deploy a revised branch configuration through Catalyst SD-WAN Manager, but edges still exchange OMP routes with Controllers and established data tunnels pass traffic. Which TWO conclusions are justified? Choose TWO.

  1. Troubleshoot the Manager deployment workflow and its reachability to the targeted devices.
  2. Move user packets through the Manager to restore the configuration task.
  3. Do not infer an immediate data-plane outage solely from the failed deployment.
  4. Replace the Validator because it distributes every configuration revision.
  5. Treat the successful tunnels as proof that the revised configuration was installed.

Correct Answers: A, C

 

Correct Answers

Answer A is correct because the failed operation is centralized configuration management, while the evidence shows the separate control and data functions still operating.

Answer C is correct because existing forwarding is explicitly observed, so a management failure alone cannot be treated as evidence that those tunnels have stopped.

Incorrect Answers

Answer B is incorrect because the Manager is not the normal transit data path, and redirecting packets does not repair a management deployment workflow.

Answer D is incorrect because the Validator orchestration role does not make it the configuration management system responsible for the described deployment.

Answer E is incorrect because existing forwarding can use the prior configuration; the desired change must be verified separately.

 

Question 4

Two branches already have valid routes and an operational IPsec overlay tunnel. A diagram routes their file-transfer packets through a cloud-hosted SD-WAN Controller merely because the Controller selected the overlay route. Which correction is needed?

  1. Move the user traffic to the Validator instead of the Controller.
  2. Assume all interbranch traffic must traverse a hub edge because Controllers are centralized.
  3. Route the packets through Manager because it displays tunnel statistics.
  4. Show user traffic on the edge-to-edge overlay path.
  5. Remove the IPsec tunnel and ask the provider to route the private service prefixes.

Correct Answer: D

 

Correct Answer

Answer D is correct because the Controller supplies control information; the WAN edges perform packet forwarding and encapsulation on the data path.

Incorrect Answers

Answer A is incorrect because the Validator performs orchestration and is not the normal transit device for established branch data tunnels.

Answer B is incorrect because centralized control does not imply a mandatory hub data topology; the stem explicitly establishes an edge-to-edge tunnel for this transfer.

Answer C is incorrect because management visibility does not make Manager part of the user-data forwarding path.

Answer E is incorrect because the operational overlay already supplies the data path; replacing it with provider routing is not required to correct the diagram.

 

Question 5

A firewall change permits edge-to-Controller control sessions but blocks edge-to-edge overlay traffic. The edges show healthy OMP relationships, yet branch applications fail. Which explanation best fits the observations?

  1. Working control sessions do not establish that the separate edge data path is permitted.
  2. Healthy OMP sessions imply the failure must be at the application server.
  3. The Manager should replace the blocked edge-to-edge path with its web connection.
  4. The Validator should advertise a larger service subnet to bypass the block.
  5. The Controller should forward the application packets inside the control session.

Correct Answer: A

 

Correct Answer

Answer A is correct because route exchange can succeed while firewall policy prevents the traffic that actually transports user packets between edges.

Incorrect Answers

Answer B is incorrect because OMP health does not validate every underlay or firewall condition needed by the edge-to-edge data tunnels.

Answer C is incorrect because a management connection does not provide the overlay forwarding service required by branch applications.

Answer D is incorrect because changing advertised scope does not open the blocked transport, and the Validator is not the service-route distributor.

Answer E is incorrect because control exchange and user-data forwarding are different functions; the Controller is not a substitute data tunnel.

 

Question 6

An authorized branch edge successfully reaches the Validator and learns the Manager and Controller addresses. A transport firewall permits the Validator exchange but denies all traffic to the learned Controller addresses. Which next outcome should the engineer expect?

  1. The edge must use the Validator as a permanent substitute Controller.
  2. Only the Manager user interface will be affected by this firewall policy.
  3. Discovery can succeed while persistent control relationships fail to form.
  4. All remote service routes must already be installed because authorization succeeded.
  5. Learning the Controller addresses makes their reachability unnecessary.

Correct Answer: C

 

Correct Answer

Answer C is correct because learning component addresses is only one onboarding step; the edge still needs permitted transport connectivity to those components.

Incorrect Answers

Answer A is incorrect because the Validator orchestration role does not replace the separate Controller function when Controller traffic is blocked.

Answer B is incorrect because the blocked destinations are the Controllers needed by the edge, not simply an operator browser session.

Answer D is incorrect because identity acceptance is not equivalent to completing control exchange and receiving usable overlay routes.

Answer E is incorrect because discovery does not establish an alternate transport for the subsequent edge-to-Controller communication.

 

Question 7

A branch temporarily loses all SD-WAN Controller connections. For this test, OMP graceful restart is enabled, the retention interval has not expired, installed routes remain valid, and IPsec keys and remote data paths remain usable. Which TWO statements are supported? Choose TWO.

  1. The branch is guaranteed to forward indefinitely without any Controller.
  2. Manager automatically becomes the branch’s OMP peer when Controllers disappear.
  3. Existing traffic may continue using retained valid routing information.
  4. New control information and continued operation beyond the retained state must not be assumed.
  5. All traffic must stop at the instant the last control session drops.

Correct Answers: C, D

 

Correct Answers

Answer C is correct because the stated graceful-restart and data-path conditions permit forwarding to continue temporarily even though Controller communication is lost.

Answer D is correct because the branch cannot receive normal Controller updates during the outage, and the stem limits the validity of retained state.

Incorrect Answers

Answer A is incorrect because retention, route validity and security state have limits; the scenario establishes only a temporary supported condition.

Answer B is incorrect because the described separation of roles does not make Manager a replacement Controller for OMP routing.

Answer E is incorrect because that ignores the explicitly enabled graceful-restart behavior and still-valid forwarding and security state.

 

Question 8

An operator sees a remote service route in the overlay, but every underlay route toward that route’s remote tunnel endpoint has disappeared. No alternate transport remains. Which response addresses the dependency preventing packet delivery?

  1. Extend OMP route retention while leaving the remote endpoint unreachable.
  2. Add another copy of the service prefix to the overlay policy.
  3. Raise the Manager dashboard polling frequency.
  4. Increase the service VPN identifier while keeping the same unreachable endpoint.
  5. Restore underlay reachability to a usable remote tunnel endpoint.

Correct Answer: E

 

Correct Answer

Answer E is correct because the overlay can describe the destination, but encapsulated packets still need a working transport route to the remote edge.

Incorrect Answers

Answer A is incorrect because longer retention may preserve control information but cannot provide the missing underlay transport path.

Answer B is incorrect because a duplicate service route does not create a transport path to the endpoint needed to carry it.

Answer C is incorrect because more frequent observation does not repair the missing forwarding path in the underlay.

Answer D is incorrect because changing segmentation identifiers does not establish transport reachability and can introduce additional mismatches.

 

Question 9

A centralized data policy is created through Manager and distributed through Controllers. A branch classifies a matching packet and applies the policy’s forwarding action locally. Which assignment correctly describes where this particular packet treatment occurs?

  1. Manager enforces the action by carrying the packet through its configuration session.
  2. The local service-side routing protocol enforces the entire centralized data policy.
  3. The provider router must interpret the enterprise policy definition.
  4. The WAN edge enforces the data-policy action on the packet.
  5. The Controller must receive each packet before its policy can be enforced.

Correct Answer: D

 

Correct Answer

Answer D is correct because centralized definition and distribution do not move packet processing into the controller; the receiving edge applies the installed data policy.

Incorrect Answers

Answer A is incorrect because Manager manages policy and devices but is not the packet transit path used for the described local action.

Answer B is incorrect because service routing supplies reachability but does not replace the WAN edge packet classification and installed data-policy actions described.

Answer C is incorrect because the SD-WAN edge implements the overlay policy; the provider need not understand that enterprise-specific policy to transport packets.

Answer E is incorrect because the Controller distributes relevant control or policy information; the edge can enforce the installed data policy locally.

 

Question 10

A branch has two transport circuits and one WAN edge. Both circuits reach the required control components and a remote edge, and each supports an independently established data tunnel. A diagram labels one circuit control-only and the other data-only solely because there are two network planes. Which correction is appropriate?

  1. Merge the control and data protocols into one session because they share circuits.
  2. Remove control reachability from one circuit to ensure the planes never share transport.
  3. Either eligible transport can carry control and data traffic.
  4. Send all branch LAN frames directly to Manager over the second circuit.
  5. Treat the two circuits as one physical failure domain because both carry control traffic.

Correct Answer: C

 

Correct Answer

Answer C is correct because different functions do not require one dedicated physical circuit per plane, and the stem establishes that both transports support the relevant connectivity.

Incorrect Answers

Answer A is incorrect because sharing transport does not remove their distinct protocol roles or turn user traffic into control messages.

Answer B is incorrect because the architectural separation does not require this restriction, which would reduce control-path diversity without meeting a stated need.

Answer D is incorrect because Manager is not the user-data transit destination, regardless of which physical circuit is used.

Answer E is incorrect because logical function sharing does not prove common physical risk; failure independence requires separate transport evidence.

 

Question 11

A retailer adds 150 branches and wants one reviewed rule governing which sites may advertise a sensitive service prefix. Today, engineers edit independent route policies at every branch. Which SD-WAN capability best addresses that specific coordination problem?

  1. Centralized control policy governing overlay route distribution.
  2. Manual route policies copied to each new edge without centralized governance.
  3. A different public transport address for every application server.
  4. A more frequent statistics refresh on the Manager dashboard.
  5. A larger bandwidth queue for the sensitive service packets.

Correct Answer: A

 

Correct Answer

Answer A is correct because the required decision is which sites learn or advertise a service prefix across the overlay, so centralized control policy addresses the repeated route-distribution edits.

Incorrect Answers

Answer B is incorrect because this retains the per-branch coordination and drift problem that the proposed capability is meant to address.

Answer C is incorrect because changing server addressing is not required to centrally control the distribution of service prefixes.

Answer D is incorrect because additional visibility does not implement the reviewed reachability rule across the branch routing domain.

Answer E is incorrect because queue allocation changes treatment of traffic already forwarded; it does not govern which branches receive the prefix.

 

Question 12

A business has usable MPLS at older branches and broadband Internet at new branches. It wants a common overlay without requiring either provider to learn every enterprise service VPN prefix. Which TWO design observations support that approach? Choose TWO.

  1. Every MPLS and Internet circuit must have identical latency for an overlay to form.
  2. Different eligible transport types can provide underlay connectivity for the overlay.
  3. The enterprise overlay can carry service routing separately from provider transport routing.
  4. An overlay removes the need to validate NAT and firewall traversal on the transports.
  5. Providers must participate directly in OMP for each enterprise VPN.

Correct Answers: B, C

 

Correct Answers

Answer B is correct because the solution can use multiple transport technologies when they meet the required endpoint and control-component reachability conditions.

Answer C is correct because providers supply reachability between transport endpoints while the overlay distributes enterprise service routes.

Incorrect Answers

Answer A is incorrect because performance affects suitability for particular traffic, but identical latency is not a prerequisite for the architectural separation.

Answer D is incorrect because transport eligibility still depends on the connectivity and traversal conditions needed by the SD-WAN components.

Answer E is incorrect because OMP operates among SD-WAN components; underlay providers do not need that role to transport the overlay.

 

Question 13

A voice application policy permits paths with loss below 1%, delay below 150 ms and jitter below 30 ms. Current measurements are: Path A 0.2%/180 ms/12 ms; Path B 0.4%/80 ms/15 ms; Path C 1.4%/60 ms/8 ms. All paths are otherwise eligible. Which path satisfies the complete stated SLA?

  1. Paths B and C.
  2. Path B only.
  3. Paths A and B.
  4. Path C only.
  5. Path A only.

Correct Answer: B

 

Correct Answer

Answer B is correct because its loss, delay and jitter are each below their respective limits; A fails delay and C fails loss despite their other favorable measurements.

Incorrect Answers

Answer A is incorrect because including C ignores the loss constraint, even though its delay is the lowest in the measurements.

Answer C is incorrect because including A ignores the delay constraint; satisfying two of three metrics is insufficient for the complete SLA.

Answer D is incorrect because C has low delay and jitter but its 1.4% loss exceeds the permitted 1%.

Answer E is incorrect because A has acceptable loss and jitter but its 180-ms delay exceeds the 150-ms ceiling.

 

Question 14

An enterprise must carry confidential branch traffic over an Internet transport it does not control. The design uses authenticated WAN edges with an established IPsec overlay. Which TWO benefits or limits correctly describe this arrangement? Choose TWO.

  1. The encrypted overlay guarantees service when the only access circuit is down.
  2. Provider capacity and packet delivery still affect the protected traffic.
  3. The overlay automatically protects the application before traffic reaches the local WAN edge.
  4. The overlay can protect traffic between its participating encryption endpoints.
  5. Encryption alone verifies that every advertised application destination is authorized.

Correct Answers: B, D

 

Correct Answers

Answer B is correct because encryption does not remove underlay congestion, loss or outages; the transport must still meet the application needs.

Answer D is correct because IPsec supplies protection over the intervening transport within the scope of the established tunnel.

Incorrect Answers

Answer A is incorrect because a protected packet still needs a physical transport path; encryption cannot carry it over a failed sole circuit.

Answer C is incorrect because the stated tunnel endpoints define the protection scope; a separate local segment is not automatically included.

Answer E is incorrect because cryptographic transport protection does not replace the intended routing and access-policy decisions.

 

Question 15

Operations needs to compare loss, latency and tunnel health across 200 branches before identifying sites for investigation. Engineers can still use each edge CLI, but collecting snapshots manually is too slow. Which SD-WAN architectural benefit most directly supports this task?

  1. Elimination of local verification once a dashboard is deployed.
  2. Centralized operational visibility through Manager and collected device telemetry.
  3. Centralized carriage of every branch packet through the Manager.
  4. Replacement of all measured data with the intended routing policy.
  5. Use of the Validator as a collector for every application transaction.

Correct Answer: B

 

Correct Answer

Answer B is correct because the task requires a consistent fleet-wide view, which management collection and presentation can provide without manually assembling every edge snapshot.

Incorrect Answers

Answer A is incorrect because centralized data can focus an investigation, but device and path validation may still be needed for a specific incident.

Answer C is incorrect because visibility can be centralized without making the management system a transit forwarding device.

Answer D is incorrect because policy intent does not show observed loss or tunnel health, so it cannot answer the stated operational question.

Answer E is incorrect because orchestration is not the fleet monitoring role described, and transaction collection is broader than the requested network metrics.

 

Question 16

A branch has one 20-Mb/s circuit and a sustained aggregate 35-Mb/s demand. There is no alternate transport, and all traffic is required by the business. A proposal claims application-aware routing alone will make every flow meet its current throughput target. Which assessment is sound?

  1. A lower SLA latency threshold creates additional forwarding capacity.
  2. Increase queue depth to satisfy every sustained throughput target.
  3. Add Controller capacity to improve the available branch service rate.
  4. A second service VPN doubles usable bandwidth on the same physical link.
  5. The proposal needs more capacity or a revised demand/service requirement.

Correct Answer: E

 

Correct Answer

Answer E is correct because path selection cannot create the missing 15 Mb/s on a sole 20-Mb/s circuit; policy may prioritize traffic but cannot satisfy all sustained demands simultaneously.

Incorrect Answers

Answer A is incorrect because a threshold changes eligibility or reporting, not the physical service rate of the only circuit.

Answer B is incorrect because more buffering can defer drops during bursts, but it cannot indefinitely transmit a sustained 35-Mb/s demand through a 20-Mb/s service rate.

Answer C is incorrect because control-plane scaling is independent of the sole access circuit’s fixed 20-Mb/s forwarding capacity.

Answer D is incorrect because logical segmentation shares the existing transport rather than creating an independent capacity resource.

 

Question 17

A branch has IP reachability to the SD-WAN components, but onboarding rejects its device identity as unauthorized. The device is not in the enterprise’s approved inventory. Which response preserves the solution’s intended onboarding controls?

  1. Treat a successful ping as sufficient evidence to accept the device certificate.
  2. Advertise the branch LAN prefix directly through the provider to bypass onboarding.
  3. Complete the authorized inventory and identity workflow.
  4. Approve the device from the observed IP address without checking its inventory identity.
  5. Change the application SLA class until identity validation succeeds.

Correct Answer: C

 

Correct Answer

Answer C is correct because transport reachability does not establish trust; the edge must satisfy the solution’s authentication and authorization prerequisites.

Incorrect Answers

Answer A is incorrect because reachability tests prove a path, not that the device identity belongs in the authorized overlay.

Answer B is incorrect because a routing workaround does not authorize the device to join the enterprise SD-WAN domain.

Answer D is incorrect because an address proves a network location rather than authorized device identity; the rejected inventory prerequisite still needs resolution.

Answer E is incorrect because performance policy is unrelated to the identity mismatch preventing control-component authentication.

 

Question 18

A branch transport interface stays up during a last-mile provider fault, but measured overlay probes show 8% loss. Another eligible transport measures 0.2% loss. The application SLA permits less than 1% loss, and policy selects a compliant path when one is available. Which conclusion follows?

  1. Declare both transports failed because they serve the same branch.
  2. Treat a successful control session as proof that the first transport meets the application SLA.
  3. Keep the first transport until its local Ethernet carrier drops.
  4. Increase the SLA loss threshold to 10% to prove the provider has recovered.
  5. Use the compliant alternate; physical interface-up status does not prove usable path quality.

Correct Answer: E

 

Correct Answer

Answer E is correct because the first transport violates the stated loss SLA even though its local link remains up. Measured path quality identifies the second eligible transport as compliant.

Incorrect Answers

Answer A is incorrect because the second transport has independent compliant measurements; the fault on one path does not establish failure of the other.

Answer B is incorrect because control connectivity can persist while packet loss harms application traffic; it is not a substitute for the supplied path-quality evidence.

Answer C is incorrect because this confuses physical link state with end-to-end quality and ignores the measured loss that already violates the application requirement.

Answer D is incorrect because relaxing the acceptance criterion does not change the measured 8% loss or demonstrate restoration of the original service requirement.

 

Question 19

During migration, a conventional routed campus remains connected to a new SD-WAN edge on the service side. The edge has healthy overlay tunnels, but remote branches cannot reach the campus prefixes because no exchange between the service routing domain and overlay has been arranged. Which design dependency is missing?

  1. Extend route-retention timers before establishing service route exchange.
  2. A requirement for the Internet provider to learn all private campus prefixes.
  3. A requirement to use identical addresses for the service and transport interfaces.
  4. A deliberate service-side routing and advertisement integration with the overlay.
  5. Change tunnel preference while leaving the service routing boundary untouched.

Correct Answer: D

 

Correct Answer

Answer D is correct because working tunnels do not automatically import every legacy campus prefix; the intended routing exchange and return reachability must be established.

Incorrect Answers

Answer A is incorrect because retention preserves previously learned state and cannot substitute for advertising the missing legacy prefixes.

Answer B is incorrect because the provider can transport the overlay without becoming the service routing authority for those prefixes.

Answer C is incorrect because service and transport roles are distinct; forcing matching addresses does not establish the missing routing exchange.

Answer E is incorrect because a different overlay transport does not import the campus prefixes that have never been integrated into overlay route distribution.

 

Question 20

A branch policy prefers a path that meets an application SLA. During a provider incident, no eligible path meets that SLA. The fallback action depends on the deployed policy. Which statement can the architect safely make without inspecting that fallback configuration?

  1. Traffic must always use the path with the least delay regardless of other metrics.
  2. A healthy Manager session proves that at least one application path satisfies the SLA.
  3. Path optimization cannot guarantee the application SLA when no eligible path satisfies it.
  4. The application must always be dropped regardless of policy.
  5. The Controller can force the provider to restore the SLA by changing the overlay prefix.

Correct Answer: C

 

Correct Answer

Answer C is correct because the available transport performance sets a real limit; whether traffic uses a degraded path or receives another treatment requires the explicit fallback policy.

Incorrect Answers

Answer A is incorrect because loss, jitter and fallback rules may also matter; the solution does not imply this universal ranking.

Answer B is incorrect because management reachability is not evidence that the application paths meet their performance limits.

Answer D is incorrect because the scenario expressly leaves fallback behavior unspecified, so a universal drop conclusion is not justified.

Answer E is incorrect because overlay route manipulation does not guarantee repair of provider performance.

 

Question 21

A wired endpoint connects to fabric edge E1. It appears in E1’s local endpoint table, but the fabric control-plane database has no corresponding registration. A remote edge cannot locate it. Which interaction should be checked first?

  1. The remote edge’s egress QoS queue depth.
  2. The endpoint registration from E1 to the fabric control-plane nodes.
  3. The Catalyst Center browser display refresh interval.
  4. Investigate the fabric border’s external default route before endpoint registration.
  5. The legacy campus BGP session beyond the external border.

Correct Answer: B

 

Correct Answer

Answer B is correct because the edge has already detected the endpoint locally, but the missing shared mapping indicates a failure in the registration path used to inform the fabric control plane.

Incorrect Answers

Answer A is incorrect because queue capacity affects packet treatment after a path is selected; it does not populate the missing endpoint-to-location mapping.

Answer C is incorrect because refreshing an operator view does not create the missing control-plane registration needed for endpoint location.

Answer D is incorrect because the unresolved destination is an internal endpoint whose registration is absent; an external default route does not repair that missing location information.

Answer E is incorrect because the endpoint belongs inside the fabric, and its absence from the control-plane database precedes any external routing handoff.

 

Question 22

An SD-Access site loses both control-plane nodes. Underlay connectivity and existing valid cached mappings at the edges remain intact. New communication toward an internal endpoint with no usable cached mapping fails, while some established traffic continues. Which explanation fits this scope of evidence?

  1. A successful established flow proves all new destinations remain reachable.
  2. Catalyst Center automatically supplies every missing runtime endpoint mapping.
  3. The control-plane nodes must normally forward every user packet.
  4. Edges lack the control-plane resolution needed for uncached internal destinations.
  5. The underlay must be entirely down because any control-plane outage removes all IP routes.

Correct Answer: D

 

Correct Answer

Answer D is correct because the control plane maintains endpoint-location information; existing usable mappings can explain continued traffic without proving that new mapping resolution works.

Incorrect Answers

Answer A is incorrect because the retained mapping for one flow does not establish resolution for a destination absent from the local cache.

Answer B is incorrect because the management system does not replace the failed fabric control-plane nodes for this runtime resolution function.

Answer C is incorrect because continued cached forwarding demonstrates that the mapping service is distinct from the normal edge data path.

Answer E is incorrect because the stem explicitly verifies underlay connectivity, so that conclusion contradicts the evidence.

 

Question 23

A fabric endpoint reaches other fabric endpoints, but cannot reach a data-center subnet outside the fabric. The data-center routers do not participate in fabric encapsulation. Which role must provide the architectural interworking between the fabric and that routed external domain?

  1. The fabric border role.
  2. The management role that provisions the handoff, without a forwarding border.
  3. An intermediate underlay node merely because it is physically between buildings.
  4. The control-plane node acting only as the endpoint mapping database.
  5. The fabric edge role alone, without a supported external handoff.

Correct Answer: A

 

Correct Answer

Answer A is correct because the border connects the fabric site to external networks and handles the handoff needed for native routed traffic outside the fabric.

Incorrect Answers

Answer B is incorrect because orchestration can configure the intended path, but a management role does not itself carry the resulting native-IP external traffic.

Answer C is incorrect because an intermediate node transports underlay packets but does not automatically assume the fabric-to-external interworking role.

Answer D is incorrect because mapping responsibility does not by itself provide external packet handoff unless the same device also has an appropriate border role.

Answer E is incorrect because endpoint attachment and overlay termination do not by themselves provide the external border interworking specified for this routed domain.

 

Question 24

An architect wants to reuse intermediate campus routers in an SD-Access underlay. They can route between fabric-node locator addresses and support the required encapsulated packet size, but cannot terminate fabric VXLAN or maintain endpoint mappings. Which TWO conclusions are appropriate? Choose TWO.

  1. They must decapsulate each transit packet and route its endpoint address.
  2. Their ability to carry small pings proves the fabric MTU requirement has been met.
  3. They can serve as intermediate underlay transit nodes if the remaining support requirements are met.
  4. They must maintain the complete endpoint-location database to forward any fabric traffic.
  5. They should not be assigned an edge role on the basis of those transport capabilities alone.

Correct Answers: C, E

 

Correct Answers

Answer C is correct because intermediate nodes need transport reachability and suitable MTU; they do not need to perform every edge or control-plane fabric function.

Answer E is correct because edge nodes need endpoint and encapsulation functions beyond ordinary underlay routing.

Incorrect Answers

Answer A is incorrect because normal intermediate forwarding uses the encapsulated packet’s transport header rather than terminating the fabric overlay.

Answer B is incorrect because small-packet reachability does not verify support for the larger encapsulated packets specified by the design.

Answer D is incorrect because the outer IP transport can be routed without assigning the control-plane mapping role to every intermediate router.

 

Question 25

Two users in the same SD-Access virtual network have different security group assignments. The design requires group-based restrictions without creating a separate virtual network for each group. Which TWO statements correctly describe this requirement? Choose TWO.

  1. A virtual network supplies a macro-segmentation boundary.
  2. Every distinct security group must be implemented as a separate physical underlay.
  3. Placing both users in one VN makes all group-based policy irrelevant.
  4. A different VXLAN outer source address alone defines the required group permission.
  5. Group-based policy can provide finer-grained communication controls within the VN.

Correct Answers: A, E

 

Correct Answers

Answer A is correct because VN separation establishes distinct forwarding domains, which is different from subdividing permitted communication between groups inside one VN.

Answer E is correct because the requirement concerns differentiated permissions among groups that retain the same macro-segment, rather than separate routing domains for every group.

Incorrect Answers

Answer B is incorrect because group-based policy does not require a separate transport network for each group.

Answer C is incorrect because sharing a VN does not eliminate the separate policy context available for finer segmentation.

Answer D is incorrect because the outer locator describes transport location, not the complete source-to-destination security-group policy.

 

Question 26

A wired endpoint moves from fabric edge E1 to E2 within the same supported endpoint subnet and VN. The control-plane database now maps it to E2, but another edge still has an old location entry. Which state best explains forwarding toward the former attachment?

  1. The provider WAN routing table must advertise the endpoint’s new access port.
  2. The sending edge has stale endpoint-location information.
  3. The external border must become the endpoint’s physical attachment switch.
  4. The endpoint’s group assignment necessarily changed because the cable moved.
  5. The endpoint must change its address whenever it changes fabric edges.

Correct Answer: B

 

Correct Answer

Answer B is correct because the central mapping has changed, but forwarding based on the old cached locator can still direct traffic toward E1 until the relevant state is updated.

Incorrect Answers

Answer A is incorrect because fabric endpoint attachment is represented by fabric location mappings, not an underlay provider route for an access port.

Answer C is incorrect because the endpoint is directly attached to E2; external interworking is not the missing location update described.

Answer D is incorrect because the stem establishes a location change, not a change in identity or authorization.

Answer E is incorrect because the scenario specifies a supported common subnet and VN in which fabric location can change independently of endpoint addressing.

 

Question 27

A fabric packet observation shows the same inner destination address before and after an endpoint moves. The outer destination changes from one fabric edge locator to another. Which conclusion best explains the observation?

  1. The packet has necessarily crossed into a different VN.
  2. The external Internet gateway has become the endpoint’s current fabric location.
  3. The endpoint must have two different application addresses because the outer address changed.
  4. The underlay routers must replace the endpoint’s application address at every hop.
  5. Endpoint identity stays fixed while transport location changes.

Correct Answer: E

 

Correct Answer

Answer E is correct because the unchanged inner address identifies the endpoint, while the changed outer locator directs encapsulated traffic to the new fabric attachment.

Incorrect Answers

Answer A is incorrect because a locator change alone does not establish a change in the endpoint’s virtual network membership.

Answer B is incorrect because the observed new locator belongs to another fabric edge, so an external gateway is not implicated by the evidence.

Answer C is incorrect because the observation expressly shows a stable inner destination; outer transport addressing is a different layer.

Answer D is incorrect because ordinary underlay transit forwards using the transport header rather than rewriting the endpoint identity to track movement.

 

Question 28

An enterprise requires two departments to have separate routing domains throughout an SD-Access site while sharing the same physical links. The design also permits a controlled shared-services handoff later. Which choice directly provides the requested macro-segmentation?

  1. One VN with group-based policy but a shared routing domain.
  2. Different management credentials for the switches serving each department.
  3. Separate fabric virtual networks with an explicit external shared-services design.
  4. Two underlay routing metrics within one departmental routing table.
  5. One VN with different DSCP values for each department.

Correct Answer: C

 

Correct Answer

Answer C is correct because VNs provide the required logical routing separation over shared infrastructure; controlled service access is then designed rather than assumed.

Incorrect Answers

Answer A is incorrect because group-based restrictions can control communication, but the requirement explicitly demands separate routing domains as well as a shared physical network.

Answer B is incorrect because administrative access separation does not create endpoint forwarding separation.

Answer D is incorrect because path preference does not create the logical isolation requested between departments.

Answer E is incorrect because QoS markings classify packet treatment and do not by themselves establish separate routing domains.

 

Question 29

An SD-Access path passes small locator pings and resolves endpoint mappings correctly. Full-size endpoint traffic fails after encapsulation. Testing finds an intermediate underlay segment limited to 1500-byte IP packets, while the encapsulated packets exceed that size. The requirement is to preserve 1500-byte endpoint packets without relying on fragmentation. Which correction addresses the failure?

  1. Refresh the endpoint mapping while retaining the 1500-byte underlay limit.
  2. Increase only the receiving endpoint MTU while leaving intermediate segments unchanged.
  3. Add another control-plane node without changing the underlay segment.
  4. Reduce every endpoint packet size and declare the original requirement satisfied.
  5. Provide a validated underlay MTU that carries the full encapsulated packets along the path.

Correct Answer: E

 

Correct Answer

Answer E is correct because the larger outer packet must traverse every intermediate segment. Small pings and correct mappings do not establish that the path supports its required packet size.

Incorrect Answers

Answer A is incorrect because the mapping is already verified and changing it does not remove the identified packet-size restriction.

Answer B is incorrect because a destination setting cannot make the constrained transit segment carry an oversized outer packet.

Answer C is incorrect because mapping redundancy does not alter the forwarding MTU on the verified bottleneck segment.

Answer D is incorrect because this may avoid oversized encapsulation but violates the explicit requirement to preserve 1500-byte endpoint packets.

 

Question 30

Catalyst Center is unavailable during maintenance. For this test, fabric edges and control-plane nodes remain operational, existing policy is installed, and their connectivity is unaffected. Which THREE expectations are reasonable? Choose THREE.

  1. New orchestration actions through Catalyst Center are unavailable during its outage.
  2. User traffic should be redirected through the identity server as a temporary gateway.
  3. Existing fabric packet forwarding need not stop merely because the management system is unavailable.
  4. The maintenance proves Catalyst Center is unnecessary for future provisioning.
  5. Runtime endpoint mapping remains a function of the surviving fabric control-plane nodes.
  6. Every edge must immediately withdraw all installed endpoint mappings.

Correct Answers: A, C, E

 

Correct Answers

Answer A is correct because the management system performing those workflows cannot execute them while it is offline.

Answer C is correct because the stated runtime fabric roles remain operational and have installed state; the management outage alone does not put Catalyst Center in the data path.

Answer E is correct because those nodes retain the role used for fabric endpoint-location information under the test assumptions.

Incorrect Answers

Answer B is incorrect because policy infrastructure is not a replacement transit data path for the available fabric nodes.

Answer D is incorrect because continued existing forwarding does not replace the management workflows required for orchestrating future changes.

Answer F is incorrect because no such behavior follows solely from management-system unavailability when the runtime control-plane nodes remain healthy.

 

Question 31

A traditional data-center router will peer with an SD-Access border. The external domain uses native IP forwarding and must learn how to return traffic to the fabric endpoint prefixes. Which TWO elements belong in the interworking design? Choose TWO.

  1. Explicit route exchange and return reachability for the intended endpoint space.
  2. A requirement that the external router decapsulate every fabric packet after a native IP handoff.
  3. A campus-wide Layer 2 extension as the only possible external connectivity method.
  4. A requirement that every data-center server implement LISP registration.
  5. An appropriate Layer 3 handoff from the fabric border to the external peer.

Correct Answers: A, E

 

Correct Answers

Answer A is correct because a handoff interface alone is insufficient if the external domain cannot route responses to the fabric prefixes.

Answer E is correct because the border supplies the fabric-to-native-IP transition needed by the traditional routing domain.

Incorrect Answers

Answer B is incorrect because the border terminates the fabric encapsulation for this handoff, so the native peer is not required to perform that function.

Answer C is incorrect because the scenario explicitly calls for a routed native-IP external domain, which can use a Layer 3 handoff.

Answer D is incorrect because the traditional external network can connect through a border without converting its servers into fabric control participants.

 

Question 32

Two isolated fabric VNs need DNS in a shared external services network. A VRF-aware upstream peer can selectively exchange routes, but unrestricted VN-to-VN communication is prohibited. Which design most directly matches the requirement?

  1. Merge all VN routes into one unfiltered table because DNS is shared.
  2. Use identical VN identifiers at every edge and assume shared services become reachable.
  3. Provide selective shared-services routing through the upstream peer while preserving the VN boundaries.
  4. Remove the border handoff and let the control-plane node route external DNS traffic.
  5. Install only the route toward DNS and omit routes back to the fabric endpoint space.

Correct Answer: C

 

Correct Answer

Answer C is correct because the peer can integrate the required service prefixes and return paths without indiscriminately merging the isolated departmental routing domains.

Incorrect Answers

Answer A is incorrect because sharing one service does not authorize general interdepartmental connectivity, which the requirement explicitly prohibits.

Answer B is incorrect because identifier consistency does not establish the required external routes or selective policy boundaries.

Answer D is incorrect because the mapping role does not replace the external forwarding integration provided by the border and upstream peer.

Answer E is incorrect because outbound reachability alone does not supply the bidirectional path required for the shared DNS service.

 

Question 33

Catalyst Center successfully provisions a border’s Layer 3 handoff. The adjacent traditional router has not been configured with matching interfaces or routing. The project team assumes the fabric workflow configured both sides. Which clarification is correct?

  1. Provisioning the border does not by itself configure the external nonfabric peer.
  2. The external peer must be replaced with a fabric edge before any routed handoff is possible.
  3. Successful provisioning proves that native IP traffic can already cross the handoff.
  4. A control-plane database entry eliminates the need for peer configuration.
  5. Configure only a default route on the border and assume the peer returns fabric traffic.

Correct Answer: A

 

Correct Answer

Answer A is correct because the upstream router is outside the fabric workflow’s stated automation scope, so its handoff and routing configuration must be supplied and verified separately.

Incorrect Answers

Answer B is incorrect because traditional routing peers are supported architectural participants at the external border; they require configuration, not necessarily replacement.

Answer C is incorrect because workflow completion on one side does not establish that the peer has compatible interfaces or routing.

Answer D is incorrect because endpoint-location information does not supply a working external interface or routing relationship.

Answer E is incorrect because a border default route cannot supply missing external-peer interfaces or return routes toward the endpoint prefixes.

 

Question 34

A campus must migrate one wired access area at a time to SD-Access. Its supported switches can become fabric edges, but selected endpoints in migrated and legacy areas must temporarily remain in the same Layer 2 domain with unchanged addresses. Rack and power space prevent a parallel duplicate network. Which migration approach best fits?

  1. A routed-only handoff while assuming Layer 2 broadcasts cross unchanged.
  2. An immediate renumbering of every legacy endpoint into the new fabric.
  3. An incremental conversion using a planned Layer 2 border handoff for the temporary legacy adjacency.
  4. A parallel duplicate fabric with all new hardware before any migration.
  5. A wholesale replacement of all access areas in one outage.

Correct Answer: C

 

Correct Answer

Answer C is correct because incremental reuse addresses the physical-space constraint, and a Layer 2 handoff supports the stated temporary common-domain and addressing requirement.

Incorrect Answers

Answer A is incorrect because native Layer 3 connectivity does not preserve the same Layer 2 domain explicitly required during this migration.

Answer B is incorrect because the migration requires unchanged addresses and staged movement, so this removes rather than satisfies a decisive constraint.

Answer D is incorrect because parallel migration can simplify rollback, but the stem excludes the extra rack and power resources it requires.

Answer E is incorrect because a single conversion window contradicts the required one-area-at-a-time migration strategy.

 

Question 35

A traditional switch routes through a fabric border to reach an application inside the fabric. It is not provisioned with a fabric role and has no endpoint registration or encapsulation function. A diagram marks it as a fabric edge solely because the application is reachable. Which correction is appropriate?

  1. Assume its locally attached endpoints automatically register in the fabric database.
  2. Show it as a control-plane node because it has a route to fabric prefixes.
  3. Show it as a border because it forwards traffic toward a border.
  4. Remove its routed connection because traditional devices cannot reach fabric endpoints.
  5. Show it as an external routed peer; application reachability does not confer a fabric role.

Correct Answer: E

 

Correct Answer

Answer E is correct because the border can provide interoperability with a traditional domain while that switch remains outside the fabric control and data-plane functions.

Incorrect Answers

Answer A is incorrect because the stem explicitly excludes the relevant fabric registration function on the traditional switch.

Answer B is incorrect because ordinary route knowledge does not make the switch a fabric endpoint-location database.

Answer C is incorrect because a next-hop relationship is not the same as providing the border interworking role itself.

Answer D is incorrect because the observed reachability is a valid interworking outcome; the error is the role label, not the existence of the connection.

Popular posts

img