Courseiva
Virtualization →mediumMultiple Select

CCNP Virtualization Practice Question

A network architect is designing a VXLAN EVPN fabric on Cisco Nexus 9000 switches to replace a traditional three-tier data center design. The architect wants to use a distributed anycast gateway so that hosts can move between leaf switches without changing their default gateway. Which two statements correctly describe the anycast gateway design? (Choose two.)

⚠ Common exam trap

The trap here is assuming each leaf needs a unique gateway MAC, when the design deliberately shares one virtual MAC across all participating leaves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The same gateway IP and MAC address are configured on every leaf switch that hosts the VLAN

A distributed anycast gateway places the same virtual gateway IP and virtual MAC on every leaf switch that hosts the VLAN. Hosts keep a consistent default gateway no matter which leaf they attach to, and ARP is answered locally on the attached leaf. This supports seamless workload mobility and avoids stretching traffic to a central gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only the spine switches can host the anycast gateway function

    Why it's wrong here

    The anycast gateway function is configured on leaf switches because they are the devices that connect to hosts and perform VXLAN encapsulation. Spines act as the underlay and typically as EVPN route reflectors, so placing the gateway on spines would force host traffic across the fabric unnecessarily and is not the supported design.

  • ✓

    The same gateway IP and MAC address are configured on every leaf switch that hosts the VLAN

    Why this is correct

    An anycast gateway uses the same virtual IP and virtual MAC on every leaf that participates in the VLAN, so a host keeps the same default gateway regardless of which leaf it attaches to. This is what enables seamless workload mobility without re-ARPing or changing host configuration when a virtual machine moves between racks.

  • ✗

    Hosts must be reconfigured with a new default gateway each time they migrate

    Why it's wrong here

    The entire purpose of an anycast gateway is to avoid host reconfiguration during migration. Because every leaf presents the same virtual IP and MAC, a migrated host continues to use its existing default gateway settings, and ARP entries remain valid, so no host-side change is required after the workload moves.

  • ✗

    Each leaf switch must use a unique gateway MAC address to avoid duplicate MAC detection

    Why it's wrong here

    Using a unique MAC per leaf would defeat the purpose of an anycast gateway, because hosts would see a different gateway MAC after moving and would need to relearn the gateway. The design intentionally shares one virtual MAC across all participating leaf switches so the gateway identity stays consistent for every host in the VLAN.

  • ✓

    The gateway MAC is a shared virtual MAC, typically derived from the reserved Cisco anycast gateway range

    Why this is correct

    Cisco uses a reserved virtual MAC range for distributed anycast gateways, and all participating leaf switches use the same virtual MAC for a given VLAN and gateway IP. This shared identity allows the fabric to answer ARP for the gateway locally on every leaf, avoiding tromboning traffic to a central gateway.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.