mediumMultiple Select
VXLAN: Encapsulation in UDP and Up to 16 Million Networks
Which TWO statements are true about VXLAN? (Choose two.)
Quick Answer
The answer is that VXLAN supports up to 16 million logical networks and encapsulates the original Layer 2 Ethernet frame inside a UDP packet. This is correct because VXLAN, or Virtual Extensible LAN, uses a 24-bit segment ID called the VNI (VXLAN Network Identifier), which provides 2^24 or roughly 16 million unique logical networks, far exceeding the 4096 VLAN limit. The encapsulation in UDP, typically on destination port 4789, allows the Layer 2 frame to be tunneled over a Layer 3 IP underlay, enabling scalable network virtualization without physical topology changes. On the Cisco DevNet Associate 200-901 exam, this tests your understanding of overlay networking and data center virtualization; a common trap is confusing VXLAN with VLAN or assuming it uses TCP instead of UDP. Remember the mnemonic: "VXLAN's 24-bit VNI gives 16 million networks, all wrapped in UDP for Layer 3 transport."
⚠ Common exam trap
Cisco often tests the misconception that VXLAN is a pure Layer 2 technology, but the trap here is that VXLAN encapsulates Layer 2 frames into Layer 3 UDP packets, making it a Layer 2 overlay over a Layer 3 underlay.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VXLAN encapsulates Ethernet frames in UDP packets
Option B is correct because VXLAN (RFC 7348) performs MAC-in-UDP encapsulation, taking an inner Layer 2 Ethernet frame and wrapping it in an outer UDP header (destination port 4789) carried over the IP underlay, which is what allows the Layer 2 overlay to traverse a routed Layer 3 network. Option E is correct because VXLAN uses a 24-bit VXLAN Network Identifier (VNI), yielding 2^24 = 16,777,216 distinct logical segments, far exceeding the 12-bit VLAN limit of 4094. Option A is wrong because VXLAN's underlay only needs IP reachability and multicast or unicast (e.g., via EVPN) for BUM traffic; MPLS is not required. Option C is wrong because IP-in-IP is a different tunneling mechanism (protocol 4) that does not carry an inner Ethernet frame or a VNI. Option D is wrong because VXLAN is a Layer 2-over-Layer 3 overlay: it encapsulates Layer 2 frames but relies on Layer 3 IP routing in the underlay, so it does not operate at Layer 2 only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VXLAN requires MPLS in the underlay
Why it's wrong here
VXLAN tunnels over any IP-routed underlay, so MPLS is not a prerequisite; it only needs IP reachability between VTEPs. It is tempting because MPLS-based EVPN fabrics commonly carry VXLAN, making MPLS the correct underlay choice when a provider delivers Layer 3 VPN transport.
- ✓
VXLAN encapsulates Ethernet frames in UDP packets
Why this is correct
VXLAN uses MAC-in-UDP encapsulation, wrapping the original Layer 2 Ethernet frame inside a UDP datagram for transport across a Layer 3 underlay. This is the mechanism that lets Layer 2 segments extend over routed networks.
- ✗
VXLAN uses IP-in-IP encapsulation
Why it's wrong here
VXLAN uses MAC-in-UDP encapsulation, not IP-in-IP; the outer header is UDP destined for port 4789. It is tempting because IP-in-IP is a genuine tunnel encapsulation, and would be the right answer if the question asked about that protocol instead.
- ✗
VXLAN operates at Layer 2 only
Why it's wrong here
VXLAN encapsulates Layer 2 frames inside UDP/IP, so it spans Layer 2 and Layer 3 rather than operating at Layer 2 alone. It is tempting because VXLAN does extend Layer 2 segments across a routed network, which is the correct description when explaining the service it delivers to attached hosts.
- ✓
VXLAN supports up to 16 million logical networks
Why this is correct
VXLAN uses a 24-bit VXLAN Network Identifier, yielding roughly 16 million isolated segments, which satisfies the stem's requirement for massive logical network scale. This contrasts with VLAN's 12-bit limit of 4094 segments, making VXLAN suitable for multi-tenant data centres needing far more separation than traditional Layer 2 tagging allows.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-901
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps team is deploying a containerized application across multiple hosts. They need to ensure that traffic between containers on the same host is isolated from other tenants. Which network implementation best meets this requirement?
hard- A.Linux bridge with ebtables rules
- B.NAT with port forwarding
- ✓ C.VXLAN overlays with a distributed virtual switch
- D.802.1Q VLANs on the host switch
Why C: VXLAN overlays with a distributed virtual switch provide Layer 2 isolation across multiple hosts by encapsulating Ethernet frames in UDP packets (RFC 7348). This creates independent virtual networks (VXLAN segments) that can span hosts, ensuring traffic between containers on the same host is isolated from other tenants without relying on physical network topology.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.