Cisco CCNP Enterprise 350-401 ENCOR Catalyst SD-WAN and SD-Access Architecture Practice Test
Topic 02 covers catalyst sd-wan and sd-access architecture for the Cisco Certified Specialist – Enterprise Core certification. These original practice questions apply the verified 350-401 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the Cisco 350-401 ENCOR Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.
Question 1
A new Catalyst SD-WAN edge can reach its provider gateway, but it cannot complete the initial exchange that discovers the available management and control components. Existing sites continue forwarding. The configured orchestration address is unreachable from the new branch. Which component path should be investigated first?
Correct Answer: D
Correct Answer
Answer D is correct because the Validator coordinates initial control-component discovery and onboarding. Its configured address is the failing dependency identified before the new edge establishes normal controller relationships.
Incorrect Answers
Answer A is incorrect because LAN routes matter to subsequent route advertisement, whereas the evidence places the failure in discovering control components through the transport.
Answer B is incorrect because remote data tunnels are relevant after the edge obtains the required control information; they do not replace the failed initial orchestration exchange.
Answer C is incorrect because administrator access may help diagnosis, but its success does not establish reachability from the new edge to its configured orchestration endpoint.
Answer E is incorrect because an application server does not perform onboarding, and existing-site forwarding does not validate the new branch orchestration path.
Question 2
An edge advertises a new service prefix, but another branch does not learn it. Both edges retain established management sessions, and the WAN transport is reachable. The engineer must examine the component that receives OMP information and applies centralized route-distribution policy. Which investigation is appropriate?
Correct Answer: E
Correct Answer
Answer E is correct because the Controller participates in OMP exchange and centralized control policy, making it the relevant point between an advertised service route and another branch learning that route.
Incorrect Answers
Answer A is incorrect because the stated failure is absence of the prefix in overlay control information, before application return-path behavior becomes the decisive issue.
Answer B is incorrect because administrator permissions can affect visibility but do not determine whether the Controller advertises the new service prefix.
Answer C is incorrect because the Validator assists orchestration; it does not replace the Controller OMP role after onboarding.
Answer D is incorrect because the provider supplies underlay reachability; it need not learn the enterprise service prefix transported by the overlay.
Question 3
Operators cannot deploy a revised branch configuration through Catalyst SD-WAN Manager, but edges still exchange OMP routes with Controllers and established data tunnels pass traffic. Which TWO conclusions are justified? Choose TWO.
Correct Answers: A, C
Correct Answers
Answer A is correct because the failed operation is centralized configuration management, while the evidence shows the separate control and data functions still operating.
Answer C is correct because existing forwarding is explicitly observed, so a management failure alone cannot be treated as evidence that those tunnels have stopped.
Incorrect Answers
Answer B is incorrect because the Manager is not the normal transit data path, and redirecting packets does not repair a management deployment workflow.
Answer D is incorrect because the Validator orchestration role does not make it the configuration management system responsible for the described deployment.
Answer E is incorrect because existing forwarding can use the prior configuration; the desired change must be verified separately.
Question 4
Two branches already have valid routes and an operational IPsec overlay tunnel. A diagram routes their file-transfer packets through a cloud-hosted SD-WAN Controller merely because the Controller selected the overlay route. Which correction is needed?
Correct Answer: D
Correct Answer
Answer D is correct because the Controller supplies control information; the WAN edges perform packet forwarding and encapsulation on the data path.
Incorrect Answers
Answer A is incorrect because the Validator performs orchestration and is not the normal transit device for established branch data tunnels.
Answer B is incorrect because centralized control does not imply a mandatory hub data topology; the stem explicitly establishes an edge-to-edge tunnel for this transfer.
Answer C is incorrect because management visibility does not make Manager part of the user-data forwarding path.
Answer E is incorrect because the operational overlay already supplies the data path; replacing it with provider routing is not required to correct the diagram.
Question 5
A firewall change permits edge-to-Controller control sessions but blocks edge-to-edge overlay traffic. The edges show healthy OMP relationships, yet branch applications fail. Which explanation best fits the observations?
Correct Answer: A
Correct Answer
Answer A is correct because route exchange can succeed while firewall policy prevents the traffic that actually transports user packets between edges.
Incorrect Answers
Answer B is incorrect because OMP health does not validate every underlay or firewall condition needed by the edge-to-edge data tunnels.
Answer C is incorrect because a management connection does not provide the overlay forwarding service required by branch applications.
Answer D is incorrect because changing advertised scope does not open the blocked transport, and the Validator is not the service-route distributor.
Answer E is incorrect because control exchange and user-data forwarding are different functions; the Controller is not a substitute data tunnel.
Question 6
An authorized branch edge successfully reaches the Validator and learns the Manager and Controller addresses. A transport firewall permits the Validator exchange but denies all traffic to the learned Controller addresses. Which next outcome should the engineer expect?
Correct Answer: C
Correct Answer
Answer C is correct because learning component addresses is only one onboarding step; the edge still needs permitted transport connectivity to those components.
Incorrect Answers
Answer A is incorrect because the Validator orchestration role does not replace the separate Controller function when Controller traffic is blocked.
Answer B is incorrect because the blocked destinations are the Controllers needed by the edge, not simply an operator browser session.
Answer D is incorrect because identity acceptance is not equivalent to completing control exchange and receiving usable overlay routes.
Answer E is incorrect because discovery does not establish an alternate transport for the subsequent edge-to-Controller communication.
Question 7
A branch temporarily loses all SD-WAN Controller connections. For this test, OMP graceful restart is enabled, the retention interval has not expired, installed routes remain valid, and IPsec keys and remote data paths remain usable. Which TWO statements are supported? Choose TWO.
Correct Answers: C, D
Correct Answers
Answer C is correct because the stated graceful-restart and data-path conditions permit forwarding to continue temporarily even though Controller communication is lost.
Answer D is correct because the branch cannot receive normal Controller updates during the outage, and the stem limits the validity of retained state.
Incorrect Answers
Answer A is incorrect because retention, route validity and security state have limits; the scenario establishes only a temporary supported condition.
Answer B is incorrect because the described separation of roles does not make Manager a replacement Controller for OMP routing.
Answer E is incorrect because that ignores the explicitly enabled graceful-restart behavior and still-valid forwarding and security state.
Question 8
An operator sees a remote service route in the overlay, but every underlay route toward that route’s remote tunnel endpoint has disappeared. No alternate transport remains. Which response addresses the dependency preventing packet delivery?
Correct Answer: E
Correct Answer
Answer E is correct because the overlay can describe the destination, but encapsulated packets still need a working transport route to the remote edge.
Incorrect Answers
Answer A is incorrect because longer retention may preserve control information but cannot provide the missing underlay transport path.
Answer B is incorrect because a duplicate service route does not create a transport path to the endpoint needed to carry it.
Answer C is incorrect because more frequent observation does not repair the missing forwarding path in the underlay.
Answer D is incorrect because changing segmentation identifiers does not establish transport reachability and can introduce additional mismatches.
Question 9
A centralized data policy is created through Manager and distributed through Controllers. A branch classifies a matching packet and applies the policy’s forwarding action locally. Which assignment correctly describes where this particular packet treatment occurs?
Correct Answer: D
Correct Answer
Answer D is correct because centralized definition and distribution do not move packet processing into the controller; the receiving edge applies the installed data policy.
Incorrect Answers
Answer A is incorrect because Manager manages policy and devices but is not the packet transit path used for the described local action.
Answer B is incorrect because service routing supplies reachability but does not replace the WAN edge packet classification and installed data-policy actions described.
Answer C is incorrect because the SD-WAN edge implements the overlay policy; the provider need not understand that enterprise-specific policy to transport packets.
Answer E is incorrect because the Controller distributes relevant control or policy information; the edge can enforce the installed data policy locally.
Question 10
A branch has two transport circuits and one WAN edge. Both circuits reach the required control components and a remote edge, and each supports an independently established data tunnel. A diagram labels one circuit control-only and the other data-only solely because there are two network planes. Which correction is appropriate?
Correct Answer: C
Correct Answer
Answer C is correct because different functions do not require one dedicated physical circuit per plane, and the stem establishes that both transports support the relevant connectivity.
Incorrect Answers
Answer A is incorrect because sharing transport does not remove their distinct protocol roles or turn user traffic into control messages.
Answer B is incorrect because the architectural separation does not require this restriction, which would reduce control-path diversity without meeting a stated need.
Answer D is incorrect because Manager is not the user-data transit destination, regardless of which physical circuit is used.
Answer E is incorrect because logical function sharing does not prove common physical risk; failure independence requires separate transport evidence.
Question 11
A retailer adds 150 branches and wants one reviewed rule governing which sites may advertise a sensitive service prefix. Today, engineers edit independent route policies at every branch. Which SD-WAN capability best addresses that specific coordination problem?
Correct Answer: A
Correct Answer
Answer A is correct because the required decision is which sites learn or advertise a service prefix across the overlay, so centralized control policy addresses the repeated route-distribution edits.
Incorrect Answers
Answer B is incorrect because this retains the per-branch coordination and drift problem that the proposed capability is meant to address.
Answer C is incorrect because changing server addressing is not required to centrally control the distribution of service prefixes.
Answer D is incorrect because additional visibility does not implement the reviewed reachability rule across the branch routing domain.
Answer E is incorrect because queue allocation changes treatment of traffic already forwarded; it does not govern which branches receive the prefix.
Question 12
A business has usable MPLS at older branches and broadband Internet at new branches. It wants a common overlay without requiring either provider to learn every enterprise service VPN prefix. Which TWO design observations support that approach? Choose TWO.
Correct Answers: B, C
Correct Answers
Answer B is correct because the solution can use multiple transport technologies when they meet the required endpoint and control-component reachability conditions.
Answer C is correct because providers supply reachability between transport endpoints while the overlay distributes enterprise service routes.
Incorrect Answers
Answer A is incorrect because performance affects suitability for particular traffic, but identical latency is not a prerequisite for the architectural separation.
Answer D is incorrect because transport eligibility still depends on the connectivity and traversal conditions needed by the SD-WAN components.
Answer E is incorrect because OMP operates among SD-WAN components; underlay providers do not need that role to transport the overlay.
Question 13
A voice application policy permits paths with loss below 1%, delay below 150 ms and jitter below 30 ms. Current measurements are: Path A 0.2%/180 ms/12 ms; Path B 0.4%/80 ms/15 ms; Path C 1.4%/60 ms/8 ms. All paths are otherwise eligible. Which path satisfies the complete stated SLA?
Correct Answer: B
Correct Answer
Answer B is correct because its loss, delay and jitter are each below their respective limits; A fails delay and C fails loss despite their other favorable measurements.
Incorrect Answers
Answer A is incorrect because including C ignores the loss constraint, even though its delay is the lowest in the measurements.
Answer C is incorrect because including A ignores the delay constraint; satisfying two of three metrics is insufficient for the complete SLA.
Answer D is incorrect because C has low delay and jitter but its 1.4% loss exceeds the permitted 1%.
Answer E is incorrect because A has acceptable loss and jitter but its 180-ms delay exceeds the 150-ms ceiling.
Question 14
An enterprise must carry confidential branch traffic over an Internet transport it does not control. The design uses authenticated WAN edges with an established IPsec overlay. Which TWO benefits or limits correctly describe this arrangement? Choose TWO.
Correct Answers: B, D
Correct Answers
Answer B is correct because encryption does not remove underlay congestion, loss or outages; the transport must still meet the application needs.
Answer D is correct because IPsec supplies protection over the intervening transport within the scope of the established tunnel.
Incorrect Answers
Answer A is incorrect because a protected packet still needs a physical transport path; encryption cannot carry it over a failed sole circuit.
Answer C is incorrect because the stated tunnel endpoints define the protection scope; a separate local segment is not automatically included.
Answer E is incorrect because cryptographic transport protection does not replace the intended routing and access-policy decisions.
Question 15
Operations needs to compare loss, latency and tunnel health across 200 branches before identifying sites for investigation. Engineers can still use each edge CLI, but collecting snapshots manually is too slow. Which SD-WAN architectural benefit most directly supports this task?
Correct Answer: B
Correct Answer
Answer B is correct because the task requires a consistent fleet-wide view, which management collection and presentation can provide without manually assembling every edge snapshot.
Incorrect Answers
Answer A is incorrect because centralized data can focus an investigation, but device and path validation may still be needed for a specific incident.
Answer C is incorrect because visibility can be centralized without making the management system a transit forwarding device.
Answer D is incorrect because policy intent does not show observed loss or tunnel health, so it cannot answer the stated operational question.
Answer E is incorrect because orchestration is not the fleet monitoring role described, and transaction collection is broader than the requested network metrics.
Question 16
A branch has one 20-Mb/s circuit and a sustained aggregate 35-Mb/s demand. There is no alternate transport, and all traffic is required by the business. A proposal claims application-aware routing alone will make every flow meet its current throughput target. Which assessment is sound?
Correct Answer: E
Correct Answer
Answer E is correct because path selection cannot create the missing 15 Mb/s on a sole 20-Mb/s circuit; policy may prioritize traffic but cannot satisfy all sustained demands simultaneously.
Incorrect Answers
Answer A is incorrect because a threshold changes eligibility or reporting, not the physical service rate of the only circuit.
Answer B is incorrect because more buffering can defer drops during bursts, but it cannot indefinitely transmit a sustained 35-Mb/s demand through a 20-Mb/s service rate.
Answer C is incorrect because control-plane scaling is independent of the sole access circuit’s fixed 20-Mb/s forwarding capacity.
Answer D is incorrect because logical segmentation shares the existing transport rather than creating an independent capacity resource.
Question 17
A branch has IP reachability to the SD-WAN components, but onboarding rejects its device identity as unauthorized. The device is not in the enterprise’s approved inventory. Which response preserves the solution’s intended onboarding controls?
Correct Answer: C
Correct Answer
Answer C is correct because transport reachability does not establish trust; the edge must satisfy the solution’s authentication and authorization prerequisites.
Incorrect Answers
Answer A is incorrect because reachability tests prove a path, not that the device identity belongs in the authorized overlay.
Answer B is incorrect because a routing workaround does not authorize the device to join the enterprise SD-WAN domain.
Answer D is incorrect because an address proves a network location rather than authorized device identity; the rejected inventory prerequisite still needs resolution.
Answer E is incorrect because performance policy is unrelated to the identity mismatch preventing control-component authentication.
Question 18
A branch transport interface stays up during a last-mile provider fault, but measured overlay probes show 8% loss. Another eligible transport measures 0.2% loss. The application SLA permits less than 1% loss, and policy selects a compliant path when one is available. Which conclusion follows?
Correct Answer: E
Correct Answer
Answer E is correct because the first transport violates the stated loss SLA even though its local link remains up. Measured path quality identifies the second eligible transport as compliant.
Incorrect Answers
Answer A is incorrect because the second transport has independent compliant measurements; the fault on one path does not establish failure of the other.
Answer B is incorrect because control connectivity can persist while packet loss harms application traffic; it is not a substitute for the supplied path-quality evidence.
Answer C is incorrect because this confuses physical link state with end-to-end quality and ignores the measured loss that already violates the application requirement.
Answer D is incorrect because relaxing the acceptance criterion does not change the measured 8% loss or demonstrate restoration of the original service requirement.
Question 19
During migration, a conventional routed campus remains connected to a new SD-WAN edge on the service side. The edge has healthy overlay tunnels, but remote branches cannot reach the campus prefixes because no exchange between the service routing domain and overlay has been arranged. Which design dependency is missing?
Correct Answer: D
Correct Answer
Answer D is correct because working tunnels do not automatically import every legacy campus prefix; the intended routing exchange and return reachability must be established.
Incorrect Answers
Answer A is incorrect because retention preserves previously learned state and cannot substitute for advertising the missing legacy prefixes.
Answer B is incorrect because the provider can transport the overlay without becoming the service routing authority for those prefixes.
Answer C is incorrect because service and transport roles are distinct; forcing matching addresses does not establish the missing routing exchange.
Answer E is incorrect because a different overlay transport does not import the campus prefixes that have never been integrated into overlay route distribution.
Question 20
A branch policy prefers a path that meets an application SLA. During a provider incident, no eligible path meets that SLA. The fallback action depends on the deployed policy. Which statement can the architect safely make without inspecting that fallback configuration?
Correct Answer: C
Correct Answer
Answer C is correct because the available transport performance sets a real limit; whether traffic uses a degraded path or receives another treatment requires the explicit fallback policy.
Incorrect Answers
Answer A is incorrect because loss, jitter and fallback rules may also matter; the solution does not imply this universal ranking.
Answer B is incorrect because management reachability is not evidence that the application paths meet their performance limits.
Answer D is incorrect because the scenario expressly leaves fallback behavior unspecified, so a universal drop conclusion is not justified.
Answer E is incorrect because overlay route manipulation does not guarantee repair of provider performance.
Question 21
A wired endpoint connects to fabric edge E1. It appears in E1’s local endpoint table, but the fabric control-plane database has no corresponding registration. A remote edge cannot locate it. Which interaction should be checked first?
Correct Answer: B
Correct Answer
Answer B is correct because the edge has already detected the endpoint locally, but the missing shared mapping indicates a failure in the registration path used to inform the fabric control plane.
Incorrect Answers
Answer A is incorrect because queue capacity affects packet treatment after a path is selected; it does not populate the missing endpoint-to-location mapping.
Answer C is incorrect because refreshing an operator view does not create the missing control-plane registration needed for endpoint location.
Answer D is incorrect because the unresolved destination is an internal endpoint whose registration is absent; an external default route does not repair that missing location information.
Answer E is incorrect because the endpoint belongs inside the fabric, and its absence from the control-plane database precedes any external routing handoff.
Question 22
An SD-Access site loses both control-plane nodes. Underlay connectivity and existing valid cached mappings at the edges remain intact. New communication toward an internal endpoint with no usable cached mapping fails, while some established traffic continues. Which explanation fits this scope of evidence?
Correct Answer: D
Correct Answer
Answer D is correct because the control plane maintains endpoint-location information; existing usable mappings can explain continued traffic without proving that new mapping resolution works.
Incorrect Answers
Answer A is incorrect because the retained mapping for one flow does not establish resolution for a destination absent from the local cache.
Answer B is incorrect because the management system does not replace the failed fabric control-plane nodes for this runtime resolution function.
Answer C is incorrect because continued cached forwarding demonstrates that the mapping service is distinct from the normal edge data path.
Answer E is incorrect because the stem explicitly verifies underlay connectivity, so that conclusion contradicts the evidence.
Question 23
A fabric endpoint reaches other fabric endpoints, but cannot reach a data-center subnet outside the fabric. The data-center routers do not participate in fabric encapsulation. Which role must provide the architectural interworking between the fabric and that routed external domain?
Correct Answer: A
Correct Answer
Answer A is correct because the border connects the fabric site to external networks and handles the handoff needed for native routed traffic outside the fabric.
Incorrect Answers
Answer B is incorrect because orchestration can configure the intended path, but a management role does not itself carry the resulting native-IP external traffic.
Answer C is incorrect because an intermediate node transports underlay packets but does not automatically assume the fabric-to-external interworking role.
Answer D is incorrect because mapping responsibility does not by itself provide external packet handoff unless the same device also has an appropriate border role.
Answer E is incorrect because endpoint attachment and overlay termination do not by themselves provide the external border interworking specified for this routed domain.
Question 24
An architect wants to reuse intermediate campus routers in an SD-Access underlay. They can route between fabric-node locator addresses and support the required encapsulated packet size, but cannot terminate fabric VXLAN or maintain endpoint mappings. Which TWO conclusions are appropriate? Choose TWO.
Correct Answers: C, E
Correct Answers
Answer C is correct because intermediate nodes need transport reachability and suitable MTU; they do not need to perform every edge or control-plane fabric function.
Answer E is correct because edge nodes need endpoint and encapsulation functions beyond ordinary underlay routing.
Incorrect Answers
Answer A is incorrect because normal intermediate forwarding uses the encapsulated packet’s transport header rather than terminating the fabric overlay.
Answer B is incorrect because small-packet reachability does not verify support for the larger encapsulated packets specified by the design.
Answer D is incorrect because the outer IP transport can be routed without assigning the control-plane mapping role to every intermediate router.
Question 25
Two users in the same SD-Access virtual network have different security group assignments. The design requires group-based restrictions without creating a separate virtual network for each group. Which TWO statements correctly describe this requirement? Choose TWO.
Correct Answers: A, E
Correct Answers
Answer A is correct because VN separation establishes distinct forwarding domains, which is different from subdividing permitted communication between groups inside one VN.
Answer E is correct because the requirement concerns differentiated permissions among groups that retain the same macro-segment, rather than separate routing domains for every group.
Incorrect Answers
Answer B is incorrect because group-based policy does not require a separate transport network for each group.
Answer C is incorrect because sharing a VN does not eliminate the separate policy context available for finer segmentation.
Answer D is incorrect because the outer locator describes transport location, not the complete source-to-destination security-group policy.
Question 26
A wired endpoint moves from fabric edge E1 to E2 within the same supported endpoint subnet and VN. The control-plane database now maps it to E2, but another edge still has an old location entry. Which state best explains forwarding toward the former attachment?
Correct Answer: B
Correct Answer
Answer B is correct because the central mapping has changed, but forwarding based on the old cached locator can still direct traffic toward E1 until the relevant state is updated.
Incorrect Answers
Answer A is incorrect because fabric endpoint attachment is represented by fabric location mappings, not an underlay provider route for an access port.
Answer C is incorrect because the endpoint is directly attached to E2; external interworking is not the missing location update described.
Answer D is incorrect because the stem establishes a location change, not a change in identity or authorization.
Answer E is incorrect because the scenario specifies a supported common subnet and VN in which fabric location can change independently of endpoint addressing.
Question 27
A fabric packet observation shows the same inner destination address before and after an endpoint moves. The outer destination changes from one fabric edge locator to another. Which conclusion best explains the observation?
Correct Answer: E
Correct Answer
Answer E is correct because the unchanged inner address identifies the endpoint, while the changed outer locator directs encapsulated traffic to the new fabric attachment.
Incorrect Answers
Answer A is incorrect because a locator change alone does not establish a change in the endpoint’s virtual network membership.
Answer B is incorrect because the observed new locator belongs to another fabric edge, so an external gateway is not implicated by the evidence.
Answer C is incorrect because the observation expressly shows a stable inner destination; outer transport addressing is a different layer.
Answer D is incorrect because ordinary underlay transit forwards using the transport header rather than rewriting the endpoint identity to track movement.
Question 28
An enterprise requires two departments to have separate routing domains throughout an SD-Access site while sharing the same physical links. The design also permits a controlled shared-services handoff later. Which choice directly provides the requested macro-segmentation?
Correct Answer: C
Correct Answer
Answer C is correct because VNs provide the required logical routing separation over shared infrastructure; controlled service access is then designed rather than assumed.
Incorrect Answers
Answer A is incorrect because group-based restrictions can control communication, but the requirement explicitly demands separate routing domains as well as a shared physical network.
Answer B is incorrect because administrative access separation does not create endpoint forwarding separation.
Answer D is incorrect because path preference does not create the logical isolation requested between departments.
Answer E is incorrect because QoS markings classify packet treatment and do not by themselves establish separate routing domains.
Question 29
An SD-Access path passes small locator pings and resolves endpoint mappings correctly. Full-size endpoint traffic fails after encapsulation. Testing finds an intermediate underlay segment limited to 1500-byte IP packets, while the encapsulated packets exceed that size. The requirement is to preserve 1500-byte endpoint packets without relying on fragmentation. Which correction addresses the failure?
Correct Answer: E
Correct Answer
Answer E is correct because the larger outer packet must traverse every intermediate segment. Small pings and correct mappings do not establish that the path supports its required packet size.
Incorrect Answers
Answer A is incorrect because the mapping is already verified and changing it does not remove the identified packet-size restriction.
Answer B is incorrect because a destination setting cannot make the constrained transit segment carry an oversized outer packet.
Answer C is incorrect because mapping redundancy does not alter the forwarding MTU on the verified bottleneck segment.
Answer D is incorrect because this may avoid oversized encapsulation but violates the explicit requirement to preserve 1500-byte endpoint packets.
Question 30
Catalyst Center is unavailable during maintenance. For this test, fabric edges and control-plane nodes remain operational, existing policy is installed, and their connectivity is unaffected. Which THREE expectations are reasonable? Choose THREE.
Correct Answers: A, C, E
Correct Answers
Answer A is correct because the management system performing those workflows cannot execute them while it is offline.
Answer C is correct because the stated runtime fabric roles remain operational and have installed state; the management outage alone does not put Catalyst Center in the data path.
Answer E is correct because those nodes retain the role used for fabric endpoint-location information under the test assumptions.
Incorrect Answers
Answer B is incorrect because policy infrastructure is not a replacement transit data path for the available fabric nodes.
Answer D is incorrect because continued existing forwarding does not replace the management workflows required for orchestrating future changes.
Answer F is incorrect because no such behavior follows solely from management-system unavailability when the runtime control-plane nodes remain healthy.
Question 31
A traditional data-center router will peer with an SD-Access border. The external domain uses native IP forwarding and must learn how to return traffic to the fabric endpoint prefixes. Which TWO elements belong in the interworking design? Choose TWO.
Correct Answers: A, E
Correct Answers
Answer A is correct because a handoff interface alone is insufficient if the external domain cannot route responses to the fabric prefixes.
Answer E is correct because the border supplies the fabric-to-native-IP transition needed by the traditional routing domain.
Incorrect Answers
Answer B is incorrect because the border terminates the fabric encapsulation for this handoff, so the native peer is not required to perform that function.
Answer C is incorrect because the scenario explicitly calls for a routed native-IP external domain, which can use a Layer 3 handoff.
Answer D is incorrect because the traditional external network can connect through a border without converting its servers into fabric control participants.
Question 32
Two isolated fabric VNs need DNS in a shared external services network. A VRF-aware upstream peer can selectively exchange routes, but unrestricted VN-to-VN communication is prohibited. Which design most directly matches the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because the peer can integrate the required service prefixes and return paths without indiscriminately merging the isolated departmental routing domains.
Incorrect Answers
Answer A is incorrect because sharing one service does not authorize general interdepartmental connectivity, which the requirement explicitly prohibits.
Answer B is incorrect because identifier consistency does not establish the required external routes or selective policy boundaries.
Answer D is incorrect because the mapping role does not replace the external forwarding integration provided by the border and upstream peer.
Answer E is incorrect because outbound reachability alone does not supply the bidirectional path required for the shared DNS service.
Question 33
Catalyst Center successfully provisions a border’s Layer 3 handoff. The adjacent traditional router has not been configured with matching interfaces or routing. The project team assumes the fabric workflow configured both sides. Which clarification is correct?
Correct Answer: A
Correct Answer
Answer A is correct because the upstream router is outside the fabric workflow’s stated automation scope, so its handoff and routing configuration must be supplied and verified separately.
Incorrect Answers
Answer B is incorrect because traditional routing peers are supported architectural participants at the external border; they require configuration, not necessarily replacement.
Answer C is incorrect because workflow completion on one side does not establish that the peer has compatible interfaces or routing.
Answer D is incorrect because endpoint-location information does not supply a working external interface or routing relationship.
Answer E is incorrect because a border default route cannot supply missing external-peer interfaces or return routes toward the endpoint prefixes.
Question 34
A campus must migrate one wired access area at a time to SD-Access. Its supported switches can become fabric edges, but selected endpoints in migrated and legacy areas must temporarily remain in the same Layer 2 domain with unchanged addresses. Rack and power space prevent a parallel duplicate network. Which migration approach best fits?
Correct Answer: C
Correct Answer
Answer C is correct because incremental reuse addresses the physical-space constraint, and a Layer 2 handoff supports the stated temporary common-domain and addressing requirement.
Incorrect Answers
Answer A is incorrect because native Layer 3 connectivity does not preserve the same Layer 2 domain explicitly required during this migration.
Answer B is incorrect because the migration requires unchanged addresses and staged movement, so this removes rather than satisfies a decisive constraint.
Answer D is incorrect because parallel migration can simplify rollback, but the stem excludes the extra rack and power resources it requires.
Answer E is incorrect because a single conversion window contradicts the required one-area-at-a-time migration strategy.
Question 35
A traditional switch routes through a fabric border to reach an application inside the fabric. It is not provisioned with a fabric role and has no endpoint registration or encapsulation function. A diagram marks it as a fabric edge solely because the application is reachable. Which correction is appropriate?
Correct Answer: E
Correct Answer
Answer E is correct because the border can provide interoperability with a traditional domain while that switch remains outside the fabric control and data-plane functions.
Incorrect Answers
Answer A is incorrect because the stem explicitly excludes the relevant fabric registration function on the traditional switch.
Answer B is incorrect because ordinary route knowledge does not make the switch a fabric endpoint-location database.
Answer C is incorrect because a next-hop relationship is not the same as providing the border interworking role itself.
Answer D is incorrect because the observed reachability is a valid interworking outcome; the error is the role label, not the existence of the connection.
Popular posts
Recent Posts
