Courseiva
mediumMultiple Choice

CCNP Practice Question: A network team is deploying a virtualized WAN…

A network team is deploying a virtualized WAN optimization appliance. The appliance must be able to process traffic at line rate on a 10 Gbps link. The hypervisor host has multiple physical NICs. Which design choice will best ensure the VM can achieve the required throughput?

⚠ Common exam trap

Cisco often tests the misconception that adding more vNICs or teaming can solve throughput issues, but the real bottleneck is the hypervisor's software switching overhead, which SR-IOV eliminates by providing direct hardware pass-through.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the VM a virtual function (VF) using SR-IOV on the physical NIC.

SR-IOV (Single Root I/O Virtualization) allows a physical NIC to present multiple virtual functions (VFs) directly to a VM, bypassing the hypervisor's virtual switch. This reduces CPU overhead and latency, enabling the VM to achieve near line-rate throughput on a 10 Gbps link by allowing direct hardware access for data plane traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assign the VM a virtual function (VF) using SR-IOV on the physical NIC.

    Why this is correct

    SR-IOV is the correct choice because it partitions a physical NIC into multiple virtual functions (VFs), each directly assigned to a VM without hypervisor involvement. The VM's vNIC maps to a VF that owns dedicated DMA queues, interrupt vectors, and packet-processing hardware, so data bypasses the software vSwitch and its CPU-intensive copying. This yields near-native throughput, low latency, and minimal host CPU overhead, making it far superior to any software-based virtualization approach.

  • ✗

    Use a standard virtual switch with a single vCPU for the VM.

    Why it's wrong here

    A standard virtual switch forwards all packets through a software data path in the hypervisor, and every frame incurs CPU cycles for classification, queuing, and copying between the physical NIC, host memory, and the guest. With only one vCPU for the VM, that single core must handle not only the VM's application workload but also the interrupt handling and I/O processing of all vSwitch traffic. A single core quickly becomes a saturation bottleneck, capping throughput to far less than the physical NIC line rate, regardless of the underlying physical hardware.

  • ✗

    Enable jumbo frames on the virtual switch only.

    Why it's wrong here

    Enabling jumbo frames on the vSwitch only is an incomplete fix because jumbo frames reduce per-packet CPU overhead and increase effective bandwidth by lowering the number of frames that need header processing. However, the fundamental bottleneck remains the software vSwitch's serialized packet-processing path; jumbo frames do not eliminate the need for the hypervisor to copy and switch each packet into and out of the VM. Furthermore, if the physical NIC or the VM's vNIC is not also configured consistently for the same MTU, packet fragmentation or drops can occur, making the performance benefit highly dependent on the entire data path.

  • ✗

    Configure the VM with multiple vNICs and use NIC teaming.

    Why it's wrong here

    NIC teaming with multiple vNICs primarily provides link-level redundancy and aggregates throughput across different flows by hashing on source and destination MAC, IP, or port fields. A single TCP or UDP flow is always pinned to one team member by the hashing algorithm, so per-connection throughput does not increase—only aggregate multimember bandwidth scales. More importantly, every packet in this configuration still traverses the virtual switch, which remains the central serialization bottleneck, so the team never removes the core CPU and software overhead that throttle a high-bandwidth workload.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.