IP-VPN to SD-WAN Migration: More Security and Centralized Policies

Describe Cisco SD-WAN design considerations (control plane design, overlay design, LAN design, high availability, redundancy, scalability, security design, QoS and multicast over SD-WAN fabric)
Answer Correct answer: B, D — SD-WAN adds built-in security and centralized, vSmart-driven application policies versus the distributed IP-VPN model.

What are two characteristics of a migration from an IP-VPN service to a Cisco SD-WAN architecture? (Choose two.)

  1. distributed control plane
  2. increased security Correct Answer
  3. increased scalability
  4. centralized application policies Correct Answer
  5. increased solution complexity

Community Votes

CD
50%
BD
50%

50% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

SD-WAN's hallmarks vs IP-VPN: centralized control/policy (vSmart) and native security. 'Distributed control plane' (A) is the opposite of SD-WAN's centralized model, so it is wrong.

Moving from a traditional IP-VPN (MPLS L3 VPN) to Cisco SD-WAN brings increased security through built-in end-to-end encryption and centralized, application-aware policies driven by the vSmart controller. SD-WAN centralizes the control plane, so a 'distributed control plane' is not a migration characteristic.

Picking A (distributed control plane): SD-WAN centralizes the control plane via vSmart; that is a key difference from IP-VPN, not a characteristic of the SD-WAN side. Choose B and D.

Community Discussion (3 comments)

PicoOstrava 👍 1 Selected: BD
https://www.cisco.com/c/en/us/solutions/enterprise-networks/sd-wan/what-is-sd-wan.html#~benefits << security being mentioned specifically together with Better application experience. Cisco boasting about ngfw features and end to end security. “ Security where you need it - when you need it #1 in threat intelligence from Talos* SD-WAN with integrated cloud security, URL filtering, Advanced Malware Protection (AMP), Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)”
neiker45 👍 1
I will agree on D because Cisco loves to say how well applications are handled by SD-WAN. C is a very marketed reason as well. So C,D. We have to remember that this is from a IP-VPN standpoint, so C will actually make quite a lot of sense.
rogerrogersson79 👍 1 Selected: CD
Ill go for C,D. Ill take "Distributed control plane" as the control plane is not central. vSmart makes is central.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

B and D are correct. Compared with a traditional IP-VPN, Cisco SD-WAN adds increased security through built-in end-to-end encryption (B) and centralized, application-aware policies pushed by the vSmart controller (D).

Why the Other Options Are Wrong

A (distributed control plane) is wrong: SD-WAN centralizes the control plane in vSmart, the opposite of distributed, so it is not an SD-WAN-side characteristic. C (increased scalability) and E (increased complexity) are not the two characteristics the question targets; the defining gains are security and centralized policy.

Community Comment Notes

The vote is split CD (50) vs BD (50). The reasoning for B and D: SD-WAN is marketed for integrated security and central application policies; vSmart centralizes policy, so 'distributed control plane' (A) is incorrect.

Official Reference

Related Analysis

Practice All 300-420 Questions

Access 150 questions with complete answers and detailed explanations.

View Full 300-420 Practice Test →

← Back to 300-420 Study Guide