Courseiva
Infrastructure →mediumMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is implementing a VXLAN overlay over an existing Layer 3 campus network. The requirement is to carry Layer 2 frames across the Layer 3 underlay. Which protocol is used to encapsulate the original Layer 2 frame for transport across the IP network?

⚠ Common exam trap

The trap here is assuming that any tunneling protocol can carry Layer 2 over Layer 3, when VXLAN specifically uses UDP encapsulation and a VNI, not GRE or MPLS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VXLAN with a UDP header

VXLAN encapsulates the original Layer 2 frame in a MAC-in-UDP format. The outer IP and UDP headers allow the encapsulated frame to be routed across a Layer 3 underlay, which is exactly what the scenario requires. Other encapsulation methods either need a different underlay or do not provide the VXLAN VNI and VTEP behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    802.1Q tagging on the underlay

    Why it's wrong here

    802.1Q tags are added to Ethernet frames on trunk links and are not routable across a Layer 3 underlay. The underlay in this scenario is Layer 3, so 802.1Q alone cannot transport the Layer 2 frame between VTEPs. It is a Layer 2 mechanism.

  • ✗

    MPLS label stack with a Layer 2 VPN

    Why it's wrong here

    MPLS Layer 2 VPNs can carry Layer 2 frames, but they require an MPLS-enabled underlay. The scenario describes an IP underlay and VXLAN, which uses UDP/IP encapsulation rather than MPLS labels. This option does not use the VXLAN data plane.

  • ✓

    VXLAN with a UDP header

    Why this is correct

    VXLAN encapsulates the original Layer 2 frame inside a MAC-in-UDP header. The 8-byte VXLAN header, UDP header, and outer IP header allow the frame to be routed across a Layer 3 underlay. This directly satisfies the scenario requirement to carry Layer 2 frames over an IP network.

  • ✗

    GRE with a protocol type of 0x6558

    Why it's wrong here

    GRE transparent Ethernet bridging uses protocol type 0x6558, but it is not the encapsulation used by VXLAN. GRE is a separate tunneling protocol and would require its own configuration; it does not provide the VXLAN VNI or the scalability features the scenario implies.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.