Courseiva
NetworkhardMultiple ChoiceObjective-mapped

350-601 ARP Flooding Practice Question

In a Cisco ACI fabric, a tenant has multiple bridge domains in the same VRF all with 'Unicast Routing' enabled and hardware proxy mode. However, endpoints in different BDs within the same VRF cannot communicate even with a contract. What is a possible reason?

⚠ Common exam trap

A common misconception is that 'ARP Flooding' must be enabled to allow endpoint discovery, but in hardware proxy mode with Unicast Routing enabled, ARP Flooding should be disabled to allow the spine proxy to handle ARP resolution for inter-BD communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The 'ARP Flooding' is enabled.

When 'Unicast Routing' is enabled on a bridge domain (BD) in hardware proxy mode, the ACI fabric relies on hardware proxy for forwarding. In this mode, ARP flooding should be disabled to prevent excessive flooding and allow the fabric to properly resolve ARP via the COOP database. If 'ARP Flooding' is enabled, the fabric floods ARP requests across all BDs, which can cause ARP resolution to fail for endpoints in different BDs because the hardware proxy expects ARP to be handled differently. This prevents inter-BD communication even with a contract in place. Therefore, having 'ARP Flooding' enabled is a possible reason for the communication failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The 'L3 Unknown Multicast Flooding' is set to flood.

    Why it's wrong here

    This setting affects multicast forwarding, not unicast communication.

  • The 'ARP Flooding' is enabled.

    Why this is correct

    In hardware proxy mode, ARP flooding should be disabled to enable proxy ARP. If enabled, the leaf will flood ARP requests and proxy behavior may not function, potentially breaking communication.

  • The contracts are unidirectional.

    Why it's wrong here

    Contracts can be unidirectional by design; that would not prevent one-way communication, but two-way would need two contracts. However, even with unidirectional, traffic should flow in the allowed direction.

  • The bridge domains are in different subnets.

    Why it's wrong here

    Different subnets require routing, which is enabled by 'Unicast Routing'. ACI can route between BDs in the same VRF via the contract.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 350-601 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.