CCNP Virtualization Practice Question
A network administrator is configuring a Cisco CSR 1000v router in a virtualized environment. The administrator needs to ensure that the virtual router can forward traffic between virtual machines on different VLANs. Which feature must be enabled on the CSR 1000v to support this?
⚠ Common exam trap
Test-takers frequently confuse features that provide security or isolation, such as VRF Lite or IPsec, with the fundamental requirement of enabling IP routing for basic inter-VLAN communication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP routing
To forward traffic between different VLANs, a Cisco CSR 1000v must have IP routing enabled. This allows the router to route packets between subnets configured on different interfaces or subinterfaces. Without IP routing, the router will not forward traffic between VLANs, regardless of other features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VRF Lite
Why it's wrong here
VRF Lite is used to create separate routing tables for traffic isolation. While it can be used with VLANs, it is not required to enable basic inter-VLAN routing. The scenario does not mention isolation; it simply requires forwarding between VLANs, so VRF Lite is unnecessary and adds complexity.
- ✗
IPsec VPN
Why it's wrong here
IPsec VPN is used to secure traffic between sites or remote users. It does not provide inter-VLAN routing. Enabling IPsec would not allow the router to forward traffic between VLANs; it would only encrypt specific flows. The core requirement is basic IP routing between subnets.
- ✓
IP routing
Why this is correct
Enabling IP routing on the Cisco CSR 1000v allows it to route traffic between different VLANs. By default, routing may be disabled. Once enabled with the 'ip routing' command, the router can forward packets between subnets, including those on different VLANs, provided interfaces are configured correctly.
- ✗
NAT
Why it's wrong here
Network Address Translation (NAT) is used to translate IP addresses, typically for internet access. It does not enable routing between VLANs. While NAT can be configured on a CSR 1000v, it is not the feature required for inter-VLAN routing. IP routing is the fundamental requirement.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.