CCNP Virtualization Practice Question
A network engineer is troubleshooting a VXLAN EVPN fabric on Cisco Nexus 9000 switches. Hosts in VLAN 100 on different leaf switches cannot communicate, even though the EVPN control plane shows the MAC addresses. The engineer suspects a problem with the VXLAN data plane. Which command should be used to verify the VXLAN tunnel endpoints (VTEPs) and their status?
⚠ Common exam trap
The trap here is assuming that control plane verification (such as BGP EVPN routes) is sufficient to confirm data plane connectivity, when in fact VXLAN tunnel status must be checked separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show nve peers
The 'show nve peers' command is used to verify the status of VXLAN tunnel endpoints and their peering relationships. It provides details such as the remote VTEP IP, VNI, and tunnel state. If the tunnel is down, this command helps identify the issue, which is critical when EVPN control plane information is present but data plane connectivity is failing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
show vxlan interface
Why it's wrong here
This command is not valid in NX-OS. While it sounds plausible, the correct command to view VXLAN interface details is 'show nve interface'. Using this invalid command would result in an error and not provide the needed information about VTEP peers.
- ✗
show bgp l2vpn evpn
Why it's wrong here
This command shows BGP EVPN routes, which are part of the control plane. Since the EVPN control plane already shows the MAC addresses, the problem is likely in the data plane. This command would not reveal the status of VXLAN tunnels or VTEP peers, so it is not the best choice for this scenario.
- ✓
show nve peers
Why this is correct
This command displays the status of VXLAN tunnel endpoints (VTEPs) and their peering relationships. It shows the IP addresses of remote VTEPs, the VNI, and the state of the tunnel. If the tunnel is down, this command will indicate that, helping the engineer identify why hosts cannot communicate despite EVPN MAC entries.
- ✗
show ip arp vrf all
Why it's wrong here
This command displays ARP entries across all VRFs, which can help verify IP-to-MAC mappings, but it does not provide information about VXLAN tunnel endpoints or their status. The issue is likely with the VXLAN data plane, so this command would not directly identify VTEP peering problems.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.