Cisco CCNP 300-425 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Cisco CCNP 300-425 Exam Dumps and Practice Test Dumps.


Question 381. Which protocol provides the SD Access fabric control plane

  1. OSPF
  2. CAPWAP
  3. LISP
  4. STP

Correct Answer: 3. LISP

Explanation:

LISP provides the control plane used by Cisco SD Access to maintain endpoint identity and location information. The fabric control plane keeps mappings between endpoint identifiers and routing locators so the network knows where clients are currently attached. When a wireless client moves between fabric access points, its location information can be updated without changing its normal network identity. The wireless controller communicates with the fabric control plane and registers wireless client information. This separation of identity from physical location is a core principle of the SD Access architecture and supports efficient mobility throughout a fabric site.

Question 382. Which encapsulation carries wireless client data in a fully integrated SD Access fabric

  1. VXLAN
  2. GRE
  3. CAPWAP data
  4. PPP

Correct Answer: 1. VXLAN

Explanation:

In a fully integrated SD Access wireless design, wireless client data is carried through the fabric using VXLAN. The access point encapsulates wireless client traffic and forwards it toward a fabric edge node. The wireless controller continues to manage the CAPWAP control plane, but normal client data does not have to travel through the controller as it does in traditional central switching. This distributed forwarding model allows wired and wireless endpoints to use the same fabric overlay and segmentation architecture. VXLAN also helps carry virtual network and security context through the SD Access fabric.

Question 383. What does a fabric wireless controller primarily handle for an AP

  1. Client VXLAN forwarding
  2. Wired access switching
  3. Internet routing
  4. CAPWAP control traffic

Correct Answer: 4. CAPWAP control traffic

Explanation:

A fabric enabled wireless controller primarily handles the CAPWAP control plane for access points. It manages AP registration, wireless configuration, policy, and other control functions. In the fully integrated SD Access wireless model, normal wireless client data does not traverse the controller through a CAPWAP data tunnel. Instead, the access point places the client traffic directly into the VXLAN fabric through the connected fabric edge node. Separating the control plane from the distributed data plane improves scalability and aligns wireless forwarding with the same fabric architecture used for wired endpoints.

Question 384. Which device connects an AP to the SD Access fabric

  1. Map server
  2. Fabric edge node
  3. Border node
  4. RADIUS server

Correct Answer: 2. Fabric edge node

Explanation:

A fabric edge node provides the attachment point through which access points and other endpoints enter the SD Access fabric. Wireless client traffic is VXLAN encapsulated by the fabric enabled AP and forwarded through the connected fabric edge. Fabric edge nodes also participate in the overlay architecture and enforce policy at the edge of the fabric. They differ from border nodes, which connect the fabric to external networks, and control plane nodes, which maintain endpoint location information. Correct fabric edge placement is therefore essential when designing a fully integrated SD Access wireless deployment.

Question 385. What does the SD Access control plane node maintain

  1. Endpoint location mappings
  2. AP antenna gain
  3. DHCP lease timers
  4. Spectrum captures

Correct Answer: 1. Endpoint location mappings

Explanation:

The SD Access control plane node maintains information that maps endpoint identity to current network location. Cisco uses LISP for this control plane function. When a wired or wireless endpoint attaches to the fabric, the control plane learns where that endpoint can be reached. When a wireless client roams to another fabric access point and therefore another routing locator, the mapping can be updated. This host tracking function allows the fabric to forward traffic toward the correct current attachment point without requiring the endpoint to change its normal network identity every time it moves.

Question 386. What is the role of a fabric border node

  1. Perform AP packet capture
  2. Supply client certificates
  3. Connect the fabric to external networks
  4. Assign wireless channels

Correct Answer: 3. Connect the fabric to external networks

Explanation:

A fabric border node connects the SD Access fabric domain to networks outside the fabric. It provides routing between virtual networks inside the fabric and external Layer 3 destinations. Border nodes can also help exchange reachability and policy information between different fabric domains. They serve a different purpose from fabric edge nodes, which connect endpoints and access points, and from control plane nodes, which maintain endpoint location mappings. Wireless client traffic that must leave the fabric eventually reaches an appropriate border node before being routed toward external enterprise, data center, WAN, or Internet destinations.

Question 387. What does an SD Access intermediate node primarily do

  1. Authenticate wireless clients
  2. Forward underlay IP traffic
  3. Register endpoint MAC addresses
  4. Terminate guest tunnels

Correct Answer: 2. Forward underlay IP traffic

Explanation:

Intermediate nodes form part of the SD Access underlay and primarily forward ordinary IP packets between fabric edge, control plane, and border nodes. They do not need detailed awareness of the virtual networks carried inside the fabric overlay. This keeps the underlay relatively simple because intermediate devices provide scalable IP transport while fabric intelligence remains concentrated at appropriate edge, border, and control plane functions. Wireless VXLAN traffic can therefore cross intermediate nodes as ordinary routed traffic while retaining its overlay information until it reaches the proper destination fabric node.

Question 388. What does a fabric AP do with wireless client data

  1. Sends all data to the controller
  2. Converts data to GRE
  3. Drops all Layer 2 traffic
  4. Encapsulates data in VXLAN

Correct Answer: 4. Encapsulates data in VXLAN

Explanation:

A fabric enabled access point directly encapsulates wireless client traffic in VXLAN before sending it toward the connected fabric edge node. This is a major difference from traditional centralized wireless designs where client data can be sent through a CAPWAP tunnel to the controller. The fabric controller still manages AP control functions, but the data path is distributed into the SD Access fabric. This design allows wireless clients to participate in the same virtual network segmentation and policy framework used by wired fabric endpoints while reducing dependency on centralized controller data forwarding.

Question 389. What information does a fabric WLC register with the control plane

  1. AP power supply status only
  2. DHCP option values
  3. Wireless client MAC and segmentation information
  4. Antenna radiation patterns

Correct Answer: 3. Wireless client MAC and segmentation information

Explanation:

A fabric enabled wireless controller communicates with the SD Access control plane and registers wireless client information such as Layer 2 MAC addresses, Security Group Tag information, and Layer 2 segmentation identifiers. This allows the fabric control plane to understand the identity and current attachment location of wireless endpoints. When a client roams, the host tracking information can be updated so traffic is sent toward the new location. The registration process therefore integrates wireless mobility with the broader SD Access control plane instead of treating wireless clients as a separate networking domain.

Question 390. Which platform automates SD Access fabric deployment

  1. Catalyst Center
  2. Wireshark
  3. Spectrum Expert
  4. DHCP server

Correct Answer: 1. Catalyst Center

Explanation:

Cisco Catalyst Center provides centralized automation and assurance for SD Access deployments. It can design, provision, and manage the fabric architecture while coordinating supported wired and wireless infrastructure. In a wireless fabric deployment, Catalyst Center can automate controller and fabric integration rather than requiring administrators to manually configure every LISP, VNID, policy, and fabric relationship. It also provides assurance capabilities that help operators monitor network health and troubleshoot issues. Cisco describes SD Access as an intent based campus architecture where Catalyst Center provides the automation layer for deploying the required fabric services.

Question 391. Which Cisco platform commonly supplies identity policy for SD Access

  1. Prime Infrastructure
  2. ISE
  3. Wireshark
  4. DHCP relay

Correct Answer: 2. ISE

Explanation:

Cisco Identity Services Engine commonly provides identity and policy services for SD Access. ISE can authenticate users and devices, assign policy information, and supply Security Group Tags that identify the security role associated with endpoint traffic. SD Access can then enforce segmentation and communication policy according to that identity rather than depending only on IP addressing. This identity based approach is useful for both wired and wireless endpoints. Catalyst Center focuses on automation and orchestration, while ISE provides the policy and identity functions needed for role based access control across the fabric.

Question 392. What does an L2 VNID represent in SD Access wireless

  1. AP radio power
  2. Controller hostname
  3. DHCP lease duration
  4. Layer 2 virtual network segmentation

Correct Answer: 4. Layer 2 virtual network segmentation

Explanation:

An L2 VNID identifies a Layer 2 virtual network segment within the SD Access fabric. Wireless fabric profiles include a client L2 VNID so client traffic can be placed into the appropriate VXLAN based segment. This allows the physical network infrastructure to support several logical networks over a common underlay. Cisco requires the L2 VNID used during SD Access wireless provisioning to be unique where required by the fabric design. VNIDs therefore provide overlay segmentation independently of traditional physical network boundaries and help unify wired and wireless virtual network behavior.

Question 393. What should be true of the L2 VNID during SD Access wireless provisioning

  1. It should be unique
  2. It should always equal the VLAN ID
  3. It must be zero
  4. It must match the AP MAC address

Correct Answer: 1. It should be unique

Explanation:

Cisco specifically states that the L2 VNID should be unique during SD Access wireless provisioning. The VNID identifies the Layer 2 virtual segment used by fabric client traffic. Duplicate or conflicting values can create ambiguity in the overlay and lead to incorrect segmentation behavior. The VNID is not simply an AP identifier or controller address. It belongs to the VXLAN based fabric architecture and represents a logical Layer 2 segment carried over the routed underlay. Proper VNID planning is therefore an important requirement when adding wireless services to an SD Access fabric.

Question 394. What valid L2 VNID range is documented for an SD Access wireless profile

  1. 1 through 4094
  2. 2 through 65519
  3. 0 through 16777215
  4. 1 through 255

Correct Answer: 3. 0 through 16777215

Explanation:

Cisco documents the valid L2 VNID range for an SD Access wireless profile as zero through 16777215. The VNID identifies the Layer 2 VXLAN segment used for client traffic within the fabric. This range is much larger than the traditional VLAN identifier range and illustrates one scalability advantage of VXLAN based overlays. Administrators still need to select values according to the overall fabric design and must avoid conflicting VNID assignments. The wireless fabric profile associates the selected L2 VNID with the intended wireless segmentation and policy configuration.

Question 395. What valid SGT range is documented for an SD Access wireless profile

  1. 1 through 4094
  2. 0 through 16777215
  3. 1 through 255
  4. 2 through 65519

Correct Answer: 4. 2 through 65519

Explanation:

Cisco documents an SGT configuration range of 2 through 65519 for the SD Access wireless fabric profile. The Security Group Tag represents identity or role based policy information associated with endpoint traffic. SGTs allow the network to enforce access policy independently of the client’s IP address or physical attachment point. This is a central element of Cisco TrustSec and SD Access segmentation. The wireless fabric profile can therefore combine the client Layer 2 VNID with an SGT so both virtual network segmentation and role based policy information are defined for the wireless service.

Question 396. What must be configured for an AP to join a fabric controller using IPv6

  1. WPA3 only
  2. IPv6 as the preferred AP mode
  3. Local switching
  4. Sniffer mode

Correct Answer: 2. IPv6 as the preferred AP mode

Explanation:

Cisco documentation states that when an access point must join the fabric controller using an IPv6 address, the preferred mode in the AP profile should be configured as IPv6. This ensures that the AP uses the intended IP version for CAPWAP controller communication in the fabric deployment. SD Access wireless supports IPv6 based control relationships alongside the VXLAN fabric data plane. Designers should therefore plan controller reachability, AP addressing, routing, and AP profile settings consistently when deploying fabric wireless infrastructure using IPv6 management and control connectivity.

Question 397. Which controller type is not supported for the referenced SD Access wireless design

  1. Catalyst 9800
  2. Catalyst 9800 CL
  3. Embedded wireless controller on Catalyst 9k
  4. Supported appliance controller

Correct Answer: 3. Embedded wireless controller on Catalyst 9k

Explanation:

Cisco documentation for the referenced SD Access wireless design states that the Embedded Wireless Controller on Catalyst 9k switches is not supported in that architecture. Supported Catalyst 9800 controller platforms can participate as fabric wireless controllers, but the embedded switch based wireless controller has specific restrictions. Platform support is important because SD Access wireless requires communication with the fabric control plane, VNID integration, fabric profiles, and other specialized functions. Designers should always verify the controller platform and software release against the supported SD Access architecture before selecting hardware for a production fabric deployment.

Question 398. Which command displays the overall wireless fabric status

  1. show wireless fabric summary
  2. show ip route
  3. show capwap client
  4. show spanning tree

Correct Answer: 1. show wireless fabric summary

Explanation:

The show wireless fabric summary command displays the overall SD Access wireless fabric status on a Catalyst 9800 controller. It is one of the verification commands Cisco documents for confirming fabric operation. Administrators can use additional commands to inspect VNID mappings, individual fabric profiles, access point configuration, client details, and site tags. Fabric verification is important because successful wireless service depends on several components working together, including controller fabric configuration, control plane registration, VNID mappings, site information, access point state, and client endpoint registration.

Question 399. Which command displays wireless fabric VNID mapping details

  1. show wireless client summary
  2. show ap summary
  3. show wireless stats
  4. show wireless fabric VNID mapping

Correct Answer: 4. show wireless fabric VNID mapping

Explanation:

The show wireless fabric VNID mapping command displays the configured wireless fabric VNID mapping information. This helps administrators verify that Layer 2 virtual network identifiers are associated with the expected wireless fabric configuration. VNID correctness is essential because VXLAN forwarding and segmentation depend on these identifiers. When clients experience fabric connectivity or segmentation problems, checking VNID mappings can help determine whether the controller has the expected overlay configuration. Cisco also provides commands for viewing fabric summaries, fabric profile details, AP configuration, site tag information, and individual wireless client state.

Question 400. What happens to the SD Access host tracking database when a wireless client roams

  1. The client must change its MAC address
  2. The endpoint location is updated
  3. The controller deletes the endpoint
  4. The AP becomes a border node

Correct Answer: 2. The endpoint location is updated

Explanation:

When a wireless endpoint roams to another access point in an SD Access fabric, the fabric control plane updates the endpoint’s location information in its host tracking database. The client can therefore remain associated with the same logical fabric identity while its current routing locator changes. This allows traffic to follow the client to its new attachment point without requiring conventional subnet changes simply because the user moved. Cisco describes the SD Access control plane as inherently supporting wireless roaming by updating the endpoint mapping whenever the client associates through a new fabric location.