350-401 Question 47
Select 3A network administrator is deploying Cisco SD-Access in their enterprise network to simplify network operations and enhance security. During the implementation, the administrator needs to understand the primary working principles of Cisco SD-Access. Which of the following statements accurately describe its principles?
- A
Cisco SD-Access uses a centralized control plane to manage policies and fabric operations.
- B
It relies on VXLAN encapsulation to provide network virtualization and segmentation.
- C
Cisco SD-Access eliminates the need for traditional routing protocols within the network fabric.
- D
The solution uses Cisco DNA Center to orchestrate and automate policies across the fabric.
- E
Endpoint identity is tied to IP addresses, making policy enforcement static and inflexible.
Show answer and explanation
Correct answers: A, B, D
Explanation
Cisco SD-Access operates based on key principles such as centralized policy management through Cisco DNA Center, network virtualization through VXLAN encapsulation, and identity-based policy enforcement. These principles enable simplified network operations, enhanced security, and scalability. However, traditional routing protocols are still used for underlay connectivity, and policies are tied to identities rather than static IP addresses to provide flexibility and adaptability.
- A. Correct.
Correct: Cisco SD-Access uses a centralized control plane, managed via Cisco DNA Center, to handle policies and fabric operations, simplifying management and ensuring consistency.
- B. Correct.
Correct: VXLAN encapsulation is a key component of Cisco SD-Access, providing network virtualization and enabling features like Layer 2 and Layer 3 segmentation.
- C. Incorrect.
Incorrect: Traditional routing protocols are still used within the underlay network of the SD-Access fabric to provide IP reachability, but the fabric overlay abstracts and simplifies network operations.
- D. Correct.
Correct: Cisco DNA Center acts as the orchestration and automation platform for Cisco SD-Access, enabling policy management, provisioning, and assurance across the fabric.
- E. Incorrect.
Incorrect: Cisco SD-Access uses identity-based networking, tying policies to endpoint identities (e.g., user or device roles) rather than IP addresses, allowing for dynamic and flexible policy enforcement.