Software-Defined Wide Area Network (SD-WAN)
An approach that runs a wide-area network from central policy, steering each application's traffic across several transport links such as MPLS, broadband and cellular.
A Software-Defined Wide Area Network carries the ideas of software-defined networking out to the links that join branch offices, data centres and cloud services. Instead of each branch router holding static routes, a logically central controller holds the policy, and an edge device at each site chooses a path for each flow according to the application, the condition of each link and the rules set centrally. The transport underneath can mix MPLS circuits, internet broadband and cellular links. NIST SP 800-215 discusses SD-WAN and sets out requirements for securing it.
SD-WAN is a routing and management approach, not a security control in itself. Because paths often cross the public internet, sites are commonly joined by encrypted overlay tunnels, and the protection depends on how those tunnels are configured. Central control also concentrates risk: the controller and its management interfaces (the control and management planes) become a high-value target. It commonly replaces a mesh of site-to-site VPN tunnels configured device by device, and it is commonly described as the networking half of Secure Access Service Edge (SASE).
Exam relevance: a scenario is likely to describe branches that want to use internet links alongside MPLS, or to route traffic by application, which points to SD-WAN. Candidates are expected to keep straight that it steers traffic rather than secures it, and that its controller needs protecting.