Courseiva
hardMultiple Choice

CCNP Practice Question: An engineer is deploying a virtual network…

An engineer is deploying a virtual network function (VNF) on a Cisco NFVIS host. The VNF requires four virtual NICs, each connected to a different network segment. The engineer creates four bridges on NFVIS and attaches each vNIC to a separate bridge. After deployment, the VNF can only communicate on the first bridge. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that bridges in NFVIS are isolated by default, when in fact they require explicit mapping to unique physical interfaces or subinterfaces to avoid Layer 2 conflicts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bridges are all mapped to the same physical interface without subinterfaces, causing a conflict.

In Cisco NFVIS, bridges are Layer 2 forwarding constructs that must be mapped to a physical interface (or subinterface) to provide external connectivity. When multiple bridges are all mapped to the same physical interface without using subinterfaces (e.g., GigabitEthernet0/0), they share the same VLAN and MAC domain, causing traffic from the second, third, and fourth bridges to be dropped or misdirected. The VNF can only communicate on the first bridge because that bridge's vNIC is the only one that successfully establishes a valid forwarding path through the physical interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The bridges are all mapped to the same physical interface without subinterfaces, causing a conflict.

    Why this is correct

    In NFVIS, every bridge must be mapped to a unique physical interface (or a VLAN subinterface), because the Linux bridge binds to the underlying netdev. When multiple bridges are all mapped to the same untagged physical NIC, only the first bridge can claim that NIC's datapath; the others receive no traffic because there is no 802.1Q tag to demultiplex frames among them. This is the classic root cause where one VNF appears up and the other VNFs have no connectivity.

  • ✗

    The VNF's operating system does not support multiple NICs.

    Why it's wrong here

    The guest OS inside the VNF almost always supports multiple NICs—modern Linux, Windows, and network OSes handle multiple virtio or ixgbevf interfaces. If the OS did not support multiple NICs, the failure would appear as missing or unrecognized interfaces inside the guest, not as a bridge-level conflict where only one VNF has connectivity. Since the symptom is at the NFVIS bridge/physical mapping layer, the guest OS capability is irrelevant to this diagnosis.

  • ✗

    The vNICs have duplicate MAC addresses.

    Why it's wrong here

    Duplicate vNIC MAC addresses would cause the bridge to fail in a different way: ARP and forwarding tables would flap, and traffic on all interfaces would be intermittent or dropped at the L2 layer. NFVIS/libvirt generates unique MAC addresses per vNIC, so this failure is not expected. Even with unique MACs, the multi-bridge-to-one-interface misconfiguration still produces the exact symptom described, so duplicate MACs are not the cause.

  • ✗

    The bridges were created in the wrong order.

    Why it's wrong here

    The order in which bridges are created in NFVIS has no effect on their operational state; bridges are declarative virtual-switch objects. A bridge works as soon as it has a valid mapping to a physical interface, regardless of whether it was created before or after another bridge. The real requirement is that each bridge has an exclusive or properly tagged subinterface mapping, not that creation follows a particular sequence.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.