300-420 Question 143
Single answerA network engineer is designing a Cisco SD-Access solution for an enterprise. The design must ensure seamless integration between the wired and wireless networks while providing central control over endpoint policies and consistent segmentation. Which architectural component of SD-Access is responsible for enforcing endpoint policies and maintaining consistent segmentation across both wired and wireless networks?
- A
Control plane
- B
Data plane
- C
Overlay network
- D
Cisco DNA Center
Show answer and explanation
Correct answer: D
Explanation
In Cisco SD-Access, Cisco DNA Center plays a key role in the architecture by serving as the central point for automation, policy enforcement, and network segmentation. It ensures that endpoint policies are consistently applied across both wired and wireless networks, enabling seamless integration and simplified management. The other components, while critical to the SD-Access architecture, do not provide centralized policy enforcement.
- A. Incorrect.
The control plane in SD-Access is responsible for managing routing information, endpoint locations, and host reachability. However, it does not directly enforce endpoint policies or segmentation.
- B. Incorrect.
The data plane is responsible for forwarding traffic based on the instructions from the control plane. It does not handle policy enforcement or segmentation directly.
- C. Incorrect.
The overlay network in SD-Access is used to establish virtual tunnels for traffic forwarding between endpoints. While it supports segmentation, it does not provide centralized policy enforcement.
- D. Correct.
Cisco DNA Center is the centralized management and automation platform for SD-Access. It provides policy enforcement, segmentation, and consistent control over wired and wireless networks, making it the correct choice.