350-501 MPLS and Segment Routing Practice Question
An engineer is designing an EVPN IRB (Integrated Routing and Bridging) solution. Which two statements about EVPN IRB are correct? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EVPN IRB uses an anycast default gateway IP and MAC that is shared across all PEs.
EVPN IRB provides bridging at Layer 2 and routing at Layer 3 with an anycast default gateway. It uses asymmetric IRB (bridging locally, routing via VRF) and symmetric IRB (both directions route). The anycast gateway MAC is shared across all PEs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EVPN IRB does not support multi-homing.
Why it's wrong here
It does support multi-homing.
- ✓
EVPN IRB uses an anycast default gateway IP and MAC that is shared across all PEs.
Why this is correct
Correct: common anycast gateway.
- ✗
EVPN IRB only supports IPv6 traffic.
Why it's wrong here
Supports both IPv4 and IPv6.
- ✗
EVPN IRB requires a separate VRF for each MAC-VRF.
Why it's wrong here
One VRF can serve multiple MAC-VRFs.
- ✓
In asymmetric IRB, routing occurs only at the ingress PE.
Why this is correct
Correct: asymmetric IRB routes at ingress only.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-501 question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-501 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-501 exam.