CCNP Infrastructure Practice Question
A network engineer is implementing VXLAN with an EVPN control plane in a data center. The engineer must ensure that the underlay network supports the required traffic and that the overlay provides optimal forwarding. Which two statements are true regarding this implementation? (Choose two.)
⚠ Common exam trap
The trap here is assuming that VXLAN always requires multicast in the underlay, but EVPN eliminates that requirement by using BGP and ingress replication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EVPN uses MP-BGP to distribute MAC and IP address reachability information.
EVPN uses MP-BGP to distribute MAC and IP reachability, enabling control-plane learning and features like ARP suppression. ARP suppression reduces broadcast traffic by allowing VTEPs to answer ARP requests locally. Multicast is not required in the underlay because EVPN uses ingress replication for BUM traffic. The underlay must be Layer 3, and VTEPs can be in different subnets as long as they are reachable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The underlay network must be a Layer 2 network to carry VXLAN traffic.
Why it's wrong here
VXLAN is designed to run over a Layer 3 underlay network. The underlay provides IP connectivity between VTEPs, and VXLAN encapsulates Layer 2 frames in UDP/IP packets. A Layer 3 underlay is typical and recommended for scalability. A Layer 2 underlay is not required and would limit the benefits of VXLAN. Therefore, this statement is false.
- ✗
EVPN requires that all VTEPs be in the same subnet.
Why it's wrong here
EVPN VTEPs can be in different subnets because they communicate over the Layer 3 underlay using IP routing. The VTEP IP addresses (RLOCs) can be in different subnets, as long as they are reachable. VXLAN tunnels are established between VTEPs across the routed underlay. Therefore, this statement is false.
- ✗
The underlay network must support multicast for BUM traffic replication.
Why it's wrong here
In VXLAN with an EVPN control plane, multicast is not required in the underlay for BUM traffic replication. EVPN uses ingress replication, where the ingress VTEP replicates BUM traffic to all remote VTEPs based on the EVPN IMET route. This eliminates the need for multicast in the underlay. While multicast can be used, it is not mandatory with EVPN. Therefore, this statement is false.
- ✓
EVPN uses MP-BGP to distribute MAC and IP address reachability information.
Why this is correct
EVPN uses MP-BGP with the EVPN address family to distribute MAC and IP reachability information among VTEPs. This provides a control plane for VXLAN, enabling features like ARP suppression, optimal forwarding, and multi-homing. The BGP EVPN routes include MAC/IP advertisement routes, IMET routes for multicast, and Ethernet segment routes. This is a fundamental aspect of EVPN-based VXLAN.
- ✓
VXLAN with EVPN supports ARP suppression to reduce broadcast traffic.
Why this is correct
EVPN can distribute MAC and IP bindings, allowing VTEPs to perform ARP suppression. When a host sends an ARP request, the local VTEP can respond on behalf of remote hosts if it has the MAC-IP binding from EVPN. This reduces ARP broadcasts in the VXLAN overlay. ARP suppression is a key benefit of EVPN-based VXLAN, improving network efficiency. Therefore, this statement is true.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.