nerdexam
Cisco

352-001 · Question #119

What is a key role for the access layer in a hierarchical network design?

The correct answer is A. The access layer provides a security, QoS, and policy trust boundary. In a hierarchical campus design, the access layer is the trust boundary where end devices connect and where QoS markings, port security, and policy enforcement are applied.

Designing Network Infrastructure

Question

What is a key role for the access layer in a hierarchical network design?

Options

  • AThe access layer provides a security, QoS, and policy trust boundary.
  • BThe access layer provides an aggregation point for services and applications.
  • CThe access layer serves as a distribution point for services and applications.
  • DThe access layer can be used to aggregate remote users.

How the community answered

(62 responses)
  • A
    89% (55)
  • B
    3% (2)
  • C
    6% (4)
  • D
    2% (1)

Why each option

In a hierarchical campus design, the access layer is the trust boundary where end devices connect and where QoS markings, port security, and policy enforcement are applied.

AThe access layer provides a security, QoS, and policy trust boundary.Correct

The access layer is the point where untrusted end devices attach to the network, making it the natural boundary for enforcing security policies such as 802.1X, port security, and DHCP snooping, as well as the QoS trust boundary where device markings are either trusted or re-marked before traffic enters the higher layers of the hierarchy.

BThe access layer provides an aggregation point for services and applications.

Aggregating services and applications is primarily a distribution layer function, not an access layer function.

CThe access layer serves as a distribution point for services and applications.

The distribution layer - not the access layer - acts as the distribution point for routing, policy, and services between the access and core layers.

DThe access layer can be used to aggregate remote users.

Aggregating remote users is typically handled at the WAN edge or core layer via VPN concentrators or remote access solutions, not the access layer.

Concept tested: Access layer role as QoS and security trust boundary

Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Campus/DesignZone/Campus_Design_Best_Practices.html

Topics

#access layer#hierarchical design#trust boundary#QoS policy

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice