350-601 ARP Flooding Practice Question
In a Cisco ACI fabric, a tenant has multiple bridge domains in the same VRF all with 'Unicast Routing' enabled and hardware proxy mode. However, endpoints in different BDs within the same VRF cannot communicate even with a contract. What is a possible reason?
⚠ Common exam trap
A common misconception is that 'ARP Flooding' must be enabled to allow endpoint discovery, but in hardware proxy mode with Unicast Routing enabled, ARP Flooding should be disabled to allow the spine proxy to handle ARP resolution for inter-BD communication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'ARP Flooding' is enabled.
When 'Unicast Routing' is enabled on a bridge domain (BD) in hardware proxy mode, the ACI fabric relies on hardware proxy for forwarding. In this mode, ARP flooding should be disabled to prevent excessive flooding and allow the fabric to properly resolve ARP via the COOP database. If 'ARP Flooding' is enabled, the fabric floods ARP requests across all BDs, which can cause ARP resolution to fail for endpoints in different BDs because the hardware proxy expects ARP to be handled differently. This prevents inter-BD communication even with a contract in place. Therefore, having 'ARP Flooding' enabled is a possible reason for the communication failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'L3 Unknown Multicast Flooding' is set to flood.
Why it's wrong here
This setting affects multicast forwarding, not unicast communication.
- ✓
The 'ARP Flooding' is enabled.
Why this is correct
In hardware proxy mode, ARP flooding should be disabled to enable proxy ARP. If enabled, the leaf will flood ARP requests and proxy behavior may not function, potentially breaking communication.
- ✗
The contracts are unidirectional.
Why it's wrong here
Contracts can be unidirectional by design; that would not prevent one-way communication, but two-way would need two contracts. However, even with unidirectional, traffic should flow in the allowed direction.
- ✗
The bridge domains are in different subnets.
Why it's wrong here
Different subnets require routing, which is enabled by 'Unicast Routing'. ACI can route between BDs in the same VRF via the contract.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-601 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.