350-401 Virtualization Practice Question
A network administrator is deploying Cisco ACI in a data center. The administrator needs to ensure that a new tenant's application profile can communicate with an external Layer 2 network that is connected to a border leaf switch. Which ACI construct must be configured to extend the tenant's bridge domain to the external network?
⚠ Common exam trap
Many exam-takers confuse L2Out with L3Out; L3Out is for routed connectivity, while L2Out is specifically for Layer 2 extension.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Layer 2 Outside (L2Out)
To extend a Cisco ACI bridge domain to an external Layer 2 network, an L2Out must be configured. This construct defines the external bridged domain and network, and is applied to a border leaf interface. It allows Layer 2 traffic to pass between the ACI fabric and external devices, preserving VLAN tags or mapping them as needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Layer 3 Outside (L3Out)
Why it's wrong here
An L3Out is used for Layer 3 connectivity to external networks, such as peering with a router via OSPF or BGP. It does not extend Layer 2 bridge domains. For Layer 2 extension, an L2Out is required. L3Out would provide routing, not bridging.
- ✗
A VXLAN tunnel to the external switch
Why it's wrong here
Cisco ACI uses VXLAN internally, but extending to an external Layer 2 network is not done by manually configuring a VXLAN tunnel. Instead, ACI provides the L2Out construct to map the external VLAN to the bridge domain. Manual VXLAN tunnels are not part of the ACI policy model.
- ✓
A Layer 2 Outside (L2Out)
Why this is correct
In Cisco ACI, an L2Out is used to extend a bridge domain to an external Layer 2 network. It is configured on a border leaf and includes an external bridged domain and an external bridged network. This allows Layer 2 connectivity between the ACI fabric and external devices, which is exactly what is needed to extend the tenant's bridge domain.
- ✗
A bridge domain with a flood scope of 'external'
Why it's wrong here
While bridge domains have flood scopes, setting it to 'external' does not automatically extend the BD to an external network. The L2Out configuration is required to define the external connection. The flood scope controls BUM traffic replication, not external connectivity.
Visual reference
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Spine-Leaf Architecture
Spine-Leaf architecture is a network topology where every lower-layer switch (leaf) connects to every upper-layer switch (spine) to provide predictable and scalable east-west traffic flow.
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.