Courseiva
mediumMultiple Select

VXLAN: Encapsulation in UDP and Up to 16 Million Networks

Which TWO statements are true about VXLAN? (Choose two.)

Quick Answer

The answer is that VXLAN supports up to 16 million logical networks and encapsulates the original Layer 2 Ethernet frame inside a UDP packet. This is correct because VXLAN, or Virtual Extensible LAN, uses a 24-bit segment ID called the VNI (VXLAN Network Identifier), which provides 2^24 or roughly 16 million unique logical networks, far exceeding the 4096 VLAN limit. The encapsulation in UDP, typically on destination port 4789, allows the Layer 2 frame to be tunneled over a Layer 3 IP underlay, enabling scalable network virtualization without physical topology changes. On the Cisco DevNet Associate 200-901 exam, this tests your understanding of overlay networking and data center virtualization; a common trap is confusing VXLAN with VLAN or assuming it uses TCP instead of UDP. Remember the mnemonic: "VXLAN's 24-bit VNI gives 16 million networks, all wrapped in UDP for Layer 3 transport."

⚠ Common exam trap

Cisco often tests the misconception that VXLAN is a pure Layer 2 technology, but the trap here is that VXLAN encapsulates Layer 2 frames into Layer 3 UDP packets, making it a Layer 2 overlay over a Layer 3 underlay.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VXLAN encapsulates Ethernet frames in UDP packets

Option B is correct because VXLAN (RFC 7348) performs MAC-in-UDP encapsulation, taking an inner Layer 2 Ethernet frame and wrapping it in an outer UDP header (destination port 4789) carried over the IP underlay, which is what allows the Layer 2 overlay to traverse a routed Layer 3 network. Option E is correct because VXLAN uses a 24-bit VXLAN Network Identifier (VNI), yielding 2^24 = 16,777,216 distinct logical segments, far exceeding the 12-bit VLAN limit of 4094. Option A is wrong because VXLAN's underlay only needs IP reachability and multicast or unicast (e.g., via EVPN) for BUM traffic; MPLS is not required. Option C is wrong because IP-in-IP is a different tunneling mechanism (protocol 4) that does not carry an inner Ethernet frame or a VNI. Option D is wrong because VXLAN is a Layer 2-over-Layer 3 overlay: it encapsulates Layer 2 frames but relies on Layer 3 IP routing in the underlay, so it does not operate at Layer 2 only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VXLAN requires MPLS in the underlay

    Why it's wrong here

    VXLAN tunnels over any IP-routed underlay, so MPLS is not a prerequisite; it only needs IP reachability between VTEPs. It is tempting because MPLS-based EVPN fabrics commonly carry VXLAN, making MPLS the correct underlay choice when a provider delivers Layer 3 VPN transport.

  • ✓

    VXLAN encapsulates Ethernet frames in UDP packets

    Why this is correct

    VXLAN uses MAC-in-UDP encapsulation, wrapping the original Layer 2 Ethernet frame inside a UDP datagram for transport across a Layer 3 underlay. This is the mechanism that lets Layer 2 segments extend over routed networks.

  • ✗

    VXLAN uses IP-in-IP encapsulation

    Why it's wrong here

    VXLAN uses MAC-in-UDP encapsulation, not IP-in-IP; the outer header is UDP destined for port 4789. It is tempting because IP-in-IP is a genuine tunnel encapsulation, and would be the right answer if the question asked about that protocol instead.

  • ✗

    VXLAN operates at Layer 2 only

    Why it's wrong here

    VXLAN encapsulates Layer 2 frames inside UDP/IP, so it spans Layer 2 and Layer 3 rather than operating at Layer 2 alone. It is tempting because VXLAN does extend Layer 2 segments across a routed network, which is the correct description when explaining the service it delivers to attached hosts.

  • ✓

    VXLAN supports up to 16 million logical networks

    Why this is correct

    VXLAN uses a 24-bit VXLAN Network Identifier, yielding roughly 16 million isolated segments, which satisfies the stem's requirement for massive logical network scale. This contrasts with VLAN's 12-bit limit of 4094 segments, making VXLAN suitable for multi-tenant data centres needing far more separation than traditional Layer 2 tagging allows.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 200-901

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A DevOps team is deploying a containerized application across multiple hosts. They need to ensure that traffic between containers on the same host is isolated from other tenants. Which network implementation best meets this requirement?

hard
  • A.Linux bridge with ebtables rules
  • B.NAT with port forwarding
  • ✓ C.VXLAN overlays with a distributed virtual switch
  • D.802.1Q VLANs on the host switch

Why C: VXLAN overlays with a distributed virtual switch provide Layer 2 isolation across multiple hosts by encapsulating Ethernet frames in UDP packets (RFC 7348). This creates independent virtual networks (VXLAN segments) that can span hosts, ensuring traffic between containers on the same host is isolated from other tenants without relying on physical network topology.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.