nerdexam
Cisco

300-420 · Question #280

Which three ways are SD-Access and ACI Fabric similar? (Choose three.)

The correct answer is A. use of Virtual Network IDs C. use of group policy F. use of overlays. Cisco SD-Access and ACI Fabric are similar in their use of Virtual Network IDs for segmentation, their reliance on group-based policies for network control, and their fundamental architecture built upon overlay networks.

Advanced Enterprise Campus Networks

Question

Which three ways are SD-Access and ACI Fabric similar? (Choose three.)

Options

  • Ause of Virtual Network IDs
  • Buse of Endpoint Groups
  • Cuse of group policy
  • Duse of Scalable Group Tags
  • Efocus on user endpoints
  • Fuse of overlays

How the community answered

(50 responses)
  • A
    88% (44)
  • B
    2% (1)
  • D
    2% (1)
  • E
    8% (4)

Why each option

Cisco SD-Access and ACI Fabric are similar in their use of Virtual Network IDs for segmentation, their reliance on group-based policies for network control, and their fundamental architecture built upon overlay networks.

Ause of Virtual Network IDsCorrect

Both SD-Access and ACI utilize identifiers, such as Virtual Network Identifiers (VNIs) in VXLAN, to create virtual networks and logically segment traffic.

Buse of Endpoint Groups

While ACI uses Endpoint Groups (EPGs) as a core construct for policy application, SD-Access primarily uses Scalable Group Tags (SGTs) and Virtual Networks for group-based policy, not EPGs in the ACI context.

Cuse of group policyCorrect

Both solutions employ a group-based policy model (e.g., Endpoint Groups in ACI, Virtual Networks and SGTs in SD-Access) to define communication rules for entities, abstracting policy from physical network details.

Duse of Scalable Group Tags

Scalable Group Tags (SGTs) are a foundational element for policy enforcement in SD-Access, typically integrated with Cisco ISE, but they are not a native or primary construct in ACI for group identification.

Efocus on user endpoints

While both manage endpoints, SD-Access has a strong focus on user endpoints in campus/branch networks, whereas ACI primarily focuses on application endpoints and services in the data center, making this statement too specific to SD-Access.

Fuse of overlaysCorrect

Both SD-Access and ACI fundamentally rely on overlay networks, typically using VXLAN encapsulation, to extend logical networks and decouple them from the underlying physical infrastructure.

Concept tested: SD-Access and ACI architectural similarities

Source: https://www.cisco.com/c/en/us/products/collateral/cloud-systems-management/application-centric-infrastructure/white-paper-c11-740700.html

Topics

#SD-Access#ACI#Network Overlays#Group-based Policy

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice