CCNP Virtualization Practice Question
A data center team is designing a VXLAN EVPN fabric on Cisco Nexus 9000 switches to replace an aging three-tier topology. They want to understand which functions are performed by the VXLAN tunnel endpoints and the EVPN control plane. Which two statements accurately describe VXLAN EVPN behavior? (Choose two.)
⚠ Common exam trap
The trap here is mixing up the 12-bit VLAN ID with the 24-bit VXLAN Network Identifier when reasoning about segment scale.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VTEPs encapsulate original Layer 2 frames inside UDP packets destined to the remote VTEP IP address.
VXLAN encapsulates original frames in UDP and delivers them to a remote VTEP's IP address, while EVPN supplies a BGP-based control plane that distributes MAC and IP reachability so flooding is minimized. The underlay is routed, the VNI field is 24 bits wide, and each VTEP requires its own unique address, so the other statements misstate fundamental VXLAN EVPN design facts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VXLAN Network Identifier is a 12-bit field, limiting each fabric to 4094 segments.
Why it's wrong here
The VXLAN Network Identifier is a 24-bit field, which supports roughly 16 million segments. The 12-bit figure describes the traditional IEEE 802.1Q VLAN tag, so confusing the two would wrongly suggest VXLAN offers no improvement in segmentation scale over VLANs.
- ✗
VXLAN requires that the underlay fabric run only Layer 2 trunks between every leaf and spine.
Why it's wrong here
VXLAN is designed to run over a Layer 3 routed underlay, typically using OSPF or IS-IS with BGP EVPN. Requiring Layer 2 trunks between every leaf and spine would reintroduce spanning-tree and scale limits, defeating the purpose of the spine-leaf fabric being deployed in this scenario.
- ✗
VTEPs must be configured with the same IP address on every leaf switch to form a single tunnel endpoint.
Why it's wrong here
Each VTEP needs a unique, routable IP address, usually a loopback, so that remote VTEPs can address tunnels to it individually. Duplicating the same IP across leaf switches would create an address conflict and break tunnel establishment, making the fabric unable to forward encapsulated traffic between leaves.
- ✓
VTEPs encapsulate original Layer 2 frames inside UDP packets destined to the remote VTEP IP address.
Why this is correct
VXLAN data plane encapsulation wraps the original Ethernet frame in a VXLAN header, then UDP, IP and a new outer Ethernet header. The outer destination IP is the remote VTEP's loopback address, which is reachable over the routed underlay. This is precisely how frames cross the Layer 3 fabric between leaf switches in the scenario.
- ✓
EVPN uses MP-BGP to distribute MAC and IP reachability information among VTEPs.
Why this is correct
EVPN is the control plane for VXLAN and runs over MP-BGP with the EVPN address family. It advertises MAC/IP advertisement routes, inclusive multicast routes and IMET routes, which lets leaf switches learn remote MAC addresses and build replication lists without relying on data plane flooding across the fabric.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.