SD-Access and ACI Fabric Similarities: VNIDs, Group Policy, and SGTs

Describe SD-Access Architecture (underlay, overlay, control and data plane, automation, wireless, and security)
Answer Correct answer: A, C, D — SD-Access and ACI both use VNIDs for overlay segmentation, apply group-based policy, and enforce it with Scalable Group Tags (SGTs).

Which three ways are SD-Access and ACI Fabric similar? (Choose three.)

  1. use of Virtual Network IDs Correct Answer
  2. use of Endpoint Groups
  3. use of group policy Correct Answer
  4. use of Scalable Group Tags Correct Answer
  5. focus on user endpoints

Community Insight

The shared DNA is overlay segmentation (VNID) + SGT-driven group policy. EPGs belong to ACI only; SD-Access uses Virtual Networks plus SGTs, not EPGs.

Both Cisco SD-Access and ACI fabrics use VXLAN with Virtual Network Identifiers (VNID) for overlay segmentation, express intent through group-based policy, and enforce that policy with Scalable Group Tags (SGTs). Endpoint Groups (EPGs) are ACI-specific and are not shared by SD-Access.

Picking B (Endpoint Groups): EPGs are an ACI construct; SD-Access does not use EPGs, so it is not a shared similarity. SGTs (D) are the common tag mechanism.

Community Discussion (3 comments)

cybman76 👍 1 Selected: AC
I think is A&C&F
salmarin 👍 2 Selected: AC
I think ACI doesn't transport SGT
TheGorn 👍 2 Selected: AD
Given the answer to 248, I'll go a,d,f.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A, C, and D are correct. Both fabrics overlay VXLAN using Virtual Network Identifiers (VNID) to segment tenants/VRFs (A). Both express intent through group-based policy (C), and both implement that policy with Scalable Group Tags (SGT) carried in the fabric (D).

Why the Other Options Are Wrong

B (Endpoint Groups) is wrong: EPGs are an ACI-specific object; SD-Access uses Virtual Networks and SGTs, not EPGs, so it is not a shared similarity. E (focus on user endpoints) is too generic to be a defining architectural similarity tested here.

Community Comment Notes

Votes are split (AC vs AD) with no aggregate. The strongest reading: VNID (A), group policy (C), and SGT (D) are the three shared mechanisms; EPGs are ACI-only.

Official Reference

Related Analysis

Practice All 300-420 Questions

Access 150 questions with complete answers and detailed explanations.

View Full 300-420 Practice Test →

← Back to 300-420 Study Guide