Courseiva
Virtualization →hardMultiple Choice

350-401 Virtualization Practice Question

A financial services company has deployed Cisco UCS servers with VMware vSphere 7.0 to host critical trading applications. The network uses Cisco Nexus 9000 switches in a VXLAN EVPN fabric with BGP as the underlay. The environment includes 50 ESXi hosts, each connected via two 40G interfaces to two different leaf switches in a VPC. The VMs are spread across multiple hosts and communicate over VXLAN. Recently, the operations team migrated a set of VMs from an old VLAN-based network to a new VXLAN segment (VNI 50000). After the migration, users report intermittent connectivity issues and packet loss. The engineering team captures traffic and notices that some VMs send ARP requests that are not being replied to, even though the target VM is active. Further analysis shows that the ARP requests are being flooded to all VTEPs, but the replies are not reaching the source. The team checks the underlay and finds no issues with BGP or routing. The NVE interfaces are up, and the VNI is configured. Which of the following is the most likely cause of the issue?

⚠ Common exam trap

Cisco often tests the distinction between data-plane flooding (which works) and control-plane advertisement (which fails), leading candidates to incorrectly blame replication lists or VPC issues instead of identifying the missing EVPN Type-2 route.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The MAC address of the target VM is not being advertised in EVPN type-2 routes because the VM's MAC is learned on a different leaf switch than expected.

The issue is that the target VM's MAC address is not being advertised via EVPN Type-2 routes from the leaf switch where it resides. When the source VM sends an ARP request, the ingress VTEP floods it to all VTEPs in the VNI's ingress replication list, but the reply from the target VM must be unicast back. If the target's MAC is not in the EVPN control plane (e.g., because it was learned on a different leaf than expected due to asymmetric MAC learning or stale entries), the reply cannot be forwarded correctly, causing intermittent connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ingress replication list is missing some VTEPs.

    Why it's wrong here

    If an ingress replication list were missing VTEPs, the source leaf would not send BUM traffic—including the initial ARP request—to the target leaf, so the target VM would never receive or answer the request. The reported failure is that ARP replies are not received, implying the request did arrive and the issue lies in the unicast MAC learning/advertisement path, not in the BUM replication list.

  • ✗

    The symmetric routing configuration is missing on the leaf switches.

    Why it's wrong here

    Symmetric IRB is only required for inter-subnet routing with EVPN integrated routing and bridging; this scenario describes a Layer 2 communication failure within the same VNI. Even if symmetric routing were absent, it would not cause the source leaf to fail to learn or advertise a VM MAC address. The root cause is missing or incomplete MAC reachability in the EVPN control plane, not routing asymmetry.

  • ✗

    The VPC configuration between the leaf switches and ESXi hosts is incorrect.

    Why it's wrong here

    A vPC misconfiguration on the leaf switches would affect all traffic for the dual-homed ESXi hosts, not just the newly deployed VNI or a single target VM. It would typically manifest as interface flaps, port-channel inconsistency, or connectivity loss for every VM on that vPC. The fact that other VMs operate correctly indicates the vPC peering and anycast LACP are functioning; the issue is isolated to the EVPN MAC advertisement for a specific VM MAC, not the port-channel/vPC topology.

  • ✓

    The MAC address of the target VM is not being advertised in EVPN type-2 routes because the VM's MAC is learned on a different leaf switch than expected.

    Why this is correct

    In EVPN, each leaf switch advertises locally learned MAC addresses via MP-BGP Type-2 routes. If the target VM's MAC is learned on a leaf different from the one the source leaf expects, or if that leaf has not advertised the route, the source leaf has no EVPN entry for that MAC. It floods the ARP request as BUM, but the reply is sent as unicast, and without a Type-2 route the source cannot properly deliver or cache the reply, leading to unidirectional communication failure.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.