Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2AutomationMedium

A network architect is designing a greenfield campus network using Cisco SD-Access. The goal is to automate the provisioning of user and device access across different departments with varying security policies. Which SD-Access component is responsible for defining and enforcing these group-based access policies?

  1. ACisco DNA Center
  2. BBorder Node (BN)
  3. CControl Plane Node (CPN)
  4. DPolicy Enforcement Point (PEP)
Show answer & explanation

Correct answer: A. Cisco DNA Center

Cisco DNA Center is the centralized management and orchestration platform for Cisco SD-Access. It's where network administrators define and manage all policies, including group-based access policies (SGTs), which are then translated and pushed to the underlying network devices for enforcement.

Why the other options are wrong

  • B. A Border Node (BN) connects the SD-Access fabric to external networks and performs policy enforcement at the fabric boundary, but policies are defined in DNA Center.
  • C. A Control Plane Node (CPN) provides host reachability information, mapping endpoints to their locations, but does not define access policies.
  • D. A Policy Enforcement Point (PEP) is a logical function (often within an Edge Node) that enforces policies, but it doesn't define them.

Cisco DNA Center in SD-Access

Cisco DNA Center is the controller and management platform for Cisco SD-Access. It provides a single user interface for designing, provisioning, applying policy, and assuring the network, translating business intent into network configurations.

  • Centralized management and orchestration.
  • Policy definition (e.g., SGTs, VNIs).
  • Network design, provisioning, and assurance.
  • Translates business intent into network configurations.

Memory trick: DNA Center is the brain that writes the rules.

More Automation questions