Courseiva
Virtualization →mediumMultiple Choice

CCNP Virtualization Practice Question

A network engineer is deploying virtual switching for a hypervisor host. The requirement is that virtual machines on the same host can communicate with each other using Layer 2 frame forwarding without any traffic leaving the physical NIC, and that VLAN tags be enforced per port profile. Which Cisco technology should be used to meet these requirements?

⚠ Common exam trap

The trap here is assuming any virtual appliance that runs on a hypervisor can also switch traffic between virtual machines on that host.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco Nexus 1000V Virtual Ethernet Module (VEM)

A virtual switch embedded in the hypervisor is needed so that same-host virtual machines exchange frames locally while still honoring VLAN and policy configuration. The Nexus 1000V VEM provides exactly this distributed virtual switching function, with the VSM supplying policy. The other listed products are virtual firewall, router and WAN optimization appliances, none of which perform virtual machine Layer 2 switching.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cisco Nexus 1000V Virtual Ethernet Module (VEM)

    Why this is correct

    The Nexus 1000V VEM runs inside the hypervisor and performs local Layer 2 forwarding between virtual machines on the same host, so intra-host traffic never traverses the physical uplink. It also enforces port profiles and VLAN policies pushed from the Virtual Supervisor Module, which matches both stated requirements.

  • ✗

    Cisco Adaptive Security Virtual Appliance (ASAv)

    Why it's wrong here

    The ASAv is a virtual firewall that inspects and filters flows between security zones. It does not provide the high-performance Layer 2 switching fabric that virtual machines on a host need for same-subnet frame forwarding, and it would introduce a hop instead of keeping traffic local to the hypervisor.

  • ✗

    Cisco Virtual Wide Area Application Services (vWAAS)

    Why it's wrong here

    vWAAS is a virtual appliance that optimizes WAN traffic through compression, caching and application acceleration. It is not a virtual switch and does not forward Layer 2 frames between virtual machines, so it cannot deliver the required intra-host switching or port-profile VLAN enforcement.

  • ✗

    Cisco Cloud Services Router 1000V (CSR 1000V)

    Why it's wrong here

    The CSR 1000V is a virtual router that forwards Layer 3 packets between subnets and can terminate VPNs. It does not act as the Layer 2 virtual switch between virtual machines on the same host, so it cannot satisfy the requirement for local frame forwarding with per-port VLAN enforcement.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.