Courseiva
mediumMultiple Choice

CCNP Practice Question: An enterprise is migrating a legacy application…

An enterprise is migrating a legacy application from a physical server to a virtual machine on a KVM-based hypervisor. The application requires direct access to a PCIe network interface card for performance reasons. The engineer needs to provide the VM with dedicated hardware access while maintaining isolation from other VMs. Which technology should the engineer use?

⚠ Common exam trap

Cisco often tests the distinction between PCI passthrough (dedicated, exclusive access) and SR-IOV (shared, but with virtual functions), and the trap here is that candidates may choose SR-IOV thinking it provides 'dedicated' access, when in fact it still involves the PF and is designed for sharing the physical NIC among multiple VMs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use PCI passthrough to assign the NIC directly to the VM.

PCI passthrough (Option A) is correct because it assigns the entire physical PCIe NIC directly to the VM, giving it exclusive, dedicated hardware access with full performance and no hypervisor overhead. This meets the requirement for direct access while maintaining isolation, as other VMs cannot use the same device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use PCI passthrough to assign the NIC directly to the VM.

    Why this is correct

    PCI passthrough uses an IOMMU such as Intel VT-d to remap the physical NIC's PCIe function directly into the guest's address space, so the VM's device driver owns the entire NIC exclusively. The hypervisor leaves the data plane, eliminating virtual switching and emulation overhead to reach native line-rate throughput. However, this dedicates the NIC to a single VM, so it cannot be shared and live migration is typically unsupported because the device is pinned.

  • ✗

    Enable SR-IOV and assign a virtual function to the VM.

    Why it's wrong here

    SR-IOV exposes a Physical Function (PF) and multiple Virtual Functions (VFs); each VF is a lightweight PCIe function assignable to a VM, but the VF shares the NIC's internal hardware with other VMs. The PF stays under hypervisor management, so although the data path bypasses the hypervisor, the VM receives only a partitioned slice of the NIC rather than the whole physical device. Since the requirement is to assign the NIC directly to one VM, SR-IOV cannot qualify because the device is not dedicated.

  • ✗

    Configure a paravirtualized network driver (virtio).

    Why it's wrong here

    virtio is a paravirtualized I/O framework where the guest and hypervisor exchange packet descriptors through shared memory rings, and the host (QEMU/vhost) performs the actual packet transmission. The VM sees a virtual NIC, not a physical hardware device, so every packet traverses hypervisor software or kernel modules, adding CPU overhead and preventing any direct hardware access. Even though virtio is more efficient than full emulation, it is still purely software-based and offers no passthrough capabilities.

  • ✗

    Attach the VM to a Linux bridge using macvtap.

    Why it's wrong here

    macvtap is a software wiring method that creates a tap device binding a VM's MAC address to a physical host interface, with the hypervisor's networking stack handling frame forwarding. It does not involve any PCIe assignment; the VM still uses a paravirtualized or emulated NIC driver, and the host's physical NIC remains shared and owned by the host. macvtap can reduce overhead compared with a traditional bridge, but it is fundamentally a virtual network interface, not a mechanism to pass physical hardware into a VM.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 350-401

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An architect is designing a virtualized environment for network functions that require direct access to physical NICs for performance. The hypervisor must support PCI passthrough. Which hypervisor type is best suited for this requirement?

easy
  • ✓ A.Type 1 hypervisor (e.g., VMware ESXi or KVM).
  • B.Type 2 hypervisor (e.g., VirtualBox or VMware Workstation).
  • C.Container runtime (e.g., Docker).
  • D.Bare-metal server without virtualization.

Why A: A Type 1 hypervisor (bare-metal) runs directly on the hardware and has direct access to physical resources, including PCIe devices. It supports PCI passthrough (e.g., Intel VT-d or AMD IOMMU), which allows a virtual machine to directly access a physical NIC without hypervisor intervention, maximizing performance for network functions. VMware ESXi and KVM are common Type 1 hypervisors that implement this capability.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.