Courseiva
Virtualization →easyMultiple Choice

CCNP Virtualization Practice Question

A network administrator is configuring a Cisco CSR 1000v router in a virtualized environment. The administrator needs to ensure that the virtual router can forward traffic between virtual machines on different VLANs. Which feature must be enabled on the CSR 1000v to support this?

⚠ Common exam trap

Test-takers frequently confuse features that provide security or isolation, such as VRF Lite or IPsec, with the fundamental requirement of enabling IP routing for basic inter-VLAN communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP routing

To forward traffic between different VLANs, a Cisco CSR 1000v must have IP routing enabled. This allows the router to route packets between subnets configured on different interfaces or subinterfaces. Without IP routing, the router will not forward traffic between VLANs, regardless of other features.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VRF Lite

    Why it's wrong here

    VRF Lite is used to create separate routing tables for traffic isolation. While it can be used with VLANs, it is not required to enable basic inter-VLAN routing. The scenario does not mention isolation; it simply requires forwarding between VLANs, so VRF Lite is unnecessary and adds complexity.

  • ✗

    IPsec VPN

    Why it's wrong here

    IPsec VPN is used to secure traffic between sites or remote users. It does not provide inter-VLAN routing. Enabling IPsec would not allow the router to forward traffic between VLANs; it would only encrypt specific flows. The core requirement is basic IP routing between subnets.

  • ✓

    IP routing

    Why this is correct

    Enabling IP routing on the Cisco CSR 1000v allows it to route traffic between different VLANs. By default, routing may be disabled. Once enabled with the 'ip routing' command, the router can forward packets between subnets, including those on different VLANs, provided interfaces are configured correctly.

  • ✗

    NAT

    Why it's wrong here

    Network Address Translation (NAT) is used to translate IP addresses, typically for internet access. It does not enable routing between VLANs. While NAT can be configured on a CSR 1000v, it is not the feature required for inter-VLAN routing. IP routing is the fundamental requirement.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.