CCNP Infrastructure Practice Question
A network engineer is implementing VXLAN with Cisco SD-Access. The engineer needs to ensure that the fabric supports Layer 2 and Layer 3 traffic between endpoints in different subnets. Which two components are required in the VXLAN data plane to achieve this? (Choose two.)
⚠ Common exam trap
Candidates often confuse control plane protocols like LISP with data plane components, or assuming that security tags like SGT are required for basic connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VXLAN Network Identifier (VNI)
In VXLAN, the data plane relies on VTEPs to encapsulate and decapsulate traffic, and VNIs to identify the overlay segments. These two components are essential for forwarding Layer 2 and Layer 3 traffic across the underlay. LISP is a control plane protocol, IS-IS is an underlay routing protocol, and SGT is for policy enforcement. Therefore, VTEP and VNI are the correct choices for the data plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VXLAN Network Identifier (VNI)
Why this is correct
The VNI is a 24-bit identifier that segments the VXLAN overlay. Each VNI represents a Layer 2 or Layer 3 segment. It is used to identify the tenant or subnet. Without VNIs, there is no separation of traffic. In SD-Access, VNIs are mapped to VRFs and subnets. They are required to differentiate traffic in the overlay. Therefore, VNI is a required component.
- ✗
Locator/ID Separation Protocol (LISP)
Why it's wrong here
LISP is used in Cisco SD-Access for control plane mapping of endpoint identities to locations, but it is not part of the VXLAN data plane. LISP handles the control plane, while VXLAN handles the data plane encapsulation. The question asks for data plane components, so LISP is not required for the data plane itself, though it is part of the overall architecture. Thus, it is not a correct choice.
- ✗
Cisco TrustSec Security Group Tag (SGT)
Why it's wrong here
SGTs are used for group-based policy enforcement in SD-Access, but they are not part of the VXLAN data plane encapsulation. They are carried in the VXLAN header (Group Policy ID) but are not a required component for basic Layer 2 and Layer 3 connectivity. The question asks for components required to achieve traffic between endpoints in different subnets, which is handled by VTEP and VNI. SGT is for policy, not basic forwarding. Thus, it is not a correct choice.
- ✓
VXLAN Tunnel Endpoint (VTEP)
Why this is correct
VTEPs are responsible for encapsulating and decapsulating VXLAN traffic. They map VLANs to VNIs and provide the overlay encapsulation. Without VTEPs, VXLAN tunnels cannot be established. In Cisco SD-Access, VTEPs are typically on fabric edge nodes. They are essential for both Layer 2 and Layer 3 overlay traffic, as they handle the encapsulation and forwarding based on VNI. Thus, VTEP is a required component.
- ✗
Intermediate System to Intermediate System (IS-IS)
Why it's wrong here
IS-IS is a routing protocol used in the underlay network of SD-Access to provide IP reachability between fabric nodes. It is not a VXLAN data plane component. The data plane encapsulation is VXLAN, not IS-IS. While IS-IS is important for the underlay, it does not directly enable Layer 2 and Layer 3 traffic between endpoints in different subnets in the overlay. Therefore, it is not a correct choice.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.