CCNP Virtualization Practice Question
A cloud provider uses Cisco ACI to automate provisioning of tenant networks. A new tenant requires a Layer 2 bridge domain that extends to an external Layer 2 network via a VPC. The engineer creates a bridge domain with the settings: Type: Regular, L2 Unknown Unicast: Flood, L3 Unknown Multicast Flood: Flood, and Multi-Destination Flooding: Flood. The VPC is configured as a virtual port channel. The tenant reports that broadcast traffic is not reaching the external network. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between bridge domain flood settings and L2Out flood settings, trapping candidates who assume that enabling flooding in the bridge domain automatically allows BUM traffic to reach external networks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The L2Out is not configured to flood BUM traffic.
The bridge domain is configured to flood BUM (Broadcast, Unknown Unicast, and Multicast) traffic internally, but the L2Out (Layer 2 external connection) must also be explicitly configured to flood BUM traffic to the external network. Without this configuration on the L2Out, the ACI fabric will not forward broadcast or multicast frames across the VPC to the external Layer 2 network, even though the bridge domain itself permits flooding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPC configuration does not support L2 extension.
Why it's wrong here
VPC (Virtual Port Channel) is a supported and commonly used deployment for L2 extension in ACI. It bundles two leaves into a single logical switch to connect an external switch/router, and the ACI fabric forwards BUM traffic across that VPC as long as the L2Out has flood enabled. Therefore the claim that VPC does not support L2 extension is false; VPC itself is an L2 extension mechanism, not a limitation.
- ✗
The bridge domain is configured as proxy mode for L2 unknown unicast.
Why it's wrong here
In an ACI bridge domain, the 'L2 Unknown Unicast' setting controls how unknown destination MAC traffic is handled. If the BD were set to proxy mode, the hardware proxy would respond and forward unknown unicasts, but that mode does not support flooding of BUM traffic across an L2Out. The actual BD configuration in this scenario is 'flood', which is the required setting for L2 extension, so the statement that it is proxy is incorrect.
- ✓
The L2Out is not configured to flood BUM traffic.
Why this is correct
An L2Out connects the ACI fabric to an external Layer 2 network, but by default BUM (broadcast, unknown unicast, multicast) traffic is not automatically flooded through every L2Out. The 'flood on' setting under the L2Out must be explicitly enabled so that BUM frames received in the BD are also sent to the external network; without it, BUM traffic is dropped or handled only locally. Since this L2Out lacks that flood configuration, the L2 extension does not actually extend L2 flooding, which explains the connectivity problem.
- ✗
The bridge domain type should be set to 'L2 Only'.
Why it's wrong here
Setting the bridge domain type to 'L2 Only' is not a prerequisite for L2 extension. A regular bridge domain, with an associated VRF, supports both L2 forwarding and L3 gateway functionality, and it can still have an L2Out attached for Layer 2 extension. Changing the BD type to L2 Only would remove the ability to route through the BD's gateway, which is unnecessary and could break other traffic; the current regular type is valid for L2 extension.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.