CCNP Virtualization Practice Question
A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN tunnel endpoint. The engineer needs to define the source IP address used for the VXLAN tunnels and ensure the switch can replicate broadcast, unknown unicast, and multicast traffic. Which configuration element must be created to source the tunnels?
⚠ Common exam trap
The trap here is assuming any routed interface can serve as the NVE source, when a stable loopback is the standard and expected choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A loopback interface with an IP address that is used as the NVE source in the interface nve1 configuration.
On a Cisco Nexus 9000, the NVE interface is used to define VXLAN tunnel endpoints, and it must reference a source interface, typically a loopback with a stable IP address. That loopback address becomes the VTEP address that remote switches use to build tunnels. The other options describe unrelated interface types or encapsulations that do not fulfill the VXLAN tunnel source requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A subinterface on the uplink port configured with encapsulation dot1q and used as the NVE source.
Why it's wrong here
A subinterface with dot1q encapsulation is used for VLAN trunking, not as a VXLAN tunnel source. The NVE source must be a routable IP address reachable by remote VTEPs, and subinterfaces are tied to physical links, reducing stability. This approach does not meet the design requirement for a resilient tunnel endpoint address.
- ✗
A tunnel interface configured with tunnel mode gre and the underlay destination as the source.
Why it's wrong here
VXLAN on Nexus 9000 uses the NVE interface, not a GRE tunnel interface. Configuring tunnel mode gre would create a different encapsulation and is not how VXLAN tunnels are sourced on this platform. The NVE interface with a loopback source is the correct construct for VXLAN tunnel endpoints.
- ✓
A loopback interface with an IP address that is used as the NVE source in the interface nve1 configuration.
Why this is correct
The NVE interface on a Nexus 9000 requires a source-interface, typically a loopback, whose IP address becomes the tunnel endpoint. This address must be reachable across the underlay so remote VTEPs can establish VXLAN tunnels. Configuring the loopback and referencing it with the source-interface command under interface nve1 is the standard method to define the tunnel source.
- ✗
A VLAN interface with the same IP address as the underlay physical interface to act as the tunnel source.
Why it's wrong here
Using a VLAN interface as the tunnel source is not the standard practice and can cause reachability and flapping issues because the VLAN interface depends on the physical link state. VXLAN tunnels should source from a stable loopback address that remains up independently of individual links. A VLAN interface does not provide the required stability or the typical anycast-style reachability.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.