CCNP Virtualization Practice Question
A network architect is designing a VXLAN EVPN fabric on Cisco Nexus 9000 switches to replace a traditional three-tier data center design. The architect wants to use a distributed anycast gateway so that hosts can move between leaf switches without changing their default gateway. Which two statements correctly describe the anycast gateway design? (Choose two.)
⚠ Common exam trap
The trap here is assuming each leaf needs a unique gateway MAC, when the design deliberately shares one virtual MAC across all participating leaves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The same gateway IP and MAC address are configured on every leaf switch that hosts the VLAN
A distributed anycast gateway places the same virtual gateway IP and virtual MAC on every leaf switch that hosts the VLAN. Hosts keep a consistent default gateway no matter which leaf they attach to, and ARP is answered locally on the attached leaf. This supports seamless workload mobility and avoids stretching traffic to a central gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only the spine switches can host the anycast gateway function
Why it's wrong here
The anycast gateway function is configured on leaf switches because they are the devices that connect to hosts and perform VXLAN encapsulation. Spines act as the underlay and typically as EVPN route reflectors, so placing the gateway on spines would force host traffic across the fabric unnecessarily and is not the supported design.
- ✓
The same gateway IP and MAC address are configured on every leaf switch that hosts the VLAN
Why this is correct
An anycast gateway uses the same virtual IP and virtual MAC on every leaf that participates in the VLAN, so a host keeps the same default gateway regardless of which leaf it attaches to. This is what enables seamless workload mobility without re-ARPing or changing host configuration when a virtual machine moves between racks.
- ✗
Hosts must be reconfigured with a new default gateway each time they migrate
Why it's wrong here
The entire purpose of an anycast gateway is to avoid host reconfiguration during migration. Because every leaf presents the same virtual IP and MAC, a migrated host continues to use its existing default gateway settings, and ARP entries remain valid, so no host-side change is required after the workload moves.
- ✗
Each leaf switch must use a unique gateway MAC address to avoid duplicate MAC detection
Why it's wrong here
Using a unique MAC per leaf would defeat the purpose of an anycast gateway, because hosts would see a different gateway MAC after moving and would need to relearn the gateway. The design intentionally shares one virtual MAC across all participating leaf switches so the gateway identity stays consistent for every host in the VLAN.
- ✓
The gateway MAC is a shared virtual MAC, typically derived from the reserved Cisco anycast gateway range
Why this is correct
Cisco uses a reserved virtual MAC range for distributed anycast gateways, and all participating leaf switches use the same virtual MAC for a given VLAN and gateway IP. This shared identity allows the fabric to answer ARP for the gateway locally on every leaf, avoiding tromboning traffic to a central gateway.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.