350-401 Virtualization Practice Question
A network architect is designing a data center fabric that uses VXLAN with an EVPN control plane on Cisco Nexus 9000 switches. The architect must justify why EVPN is preferred over a flood-and-learn VXLAN data plane. Which two statements correctly describe advantages of using an EVPN control plane in this design? (Choose two.)
⚠ Common exam trap
The trap here is conflating the overlay control plane with the underlay transport, leading to the false belief that EVPN removes the need for underlay routing or VTEP loopbacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It distributes MAC address reachability through BGP so VTEPs do not need to flood frames to learn remote host locations
An EVPN control plane advertises MAC and IP reachability via BGP, avoiding data-plane flooding for host learning, and it supports standards-based all-active multihoming through Ethernet Segment identifiers and DF election. It does not remove the underlay routing requirement, convert VXLAN to MPLS, or eliminate the VTEP loopback, so those statements are incorrect for this design.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It distributes MAC address reachability through BGP so VTEPs do not need to flood frames to learn remote host locations
Why this is correct
With EVPN, MAC and IP bindings are advertised as BGP route types, so each VTEP learns remote host locations from the control plane rather than from data-plane flooding. This reduces unknown-unicast flooding and speeds convergence. In a flood-and-learn design, every VTEP must flood to discover remote MACs, which wastes bandwidth and creates scaling problems in large fabrics.
- ✗
It converts VXLAN tunnels into MPLS LSPs to improve forwarding performance between leaf switches
Why it's wrong here
EVPN does not convert VXLAN tunnels into MPLS LSPs. VXLAN encapsulation remains MAC-in-UDP, and EVPN is purely a control plane for advertising reachability. While EVPN can run over MPLS in service provider contexts, the scenario describes a VXLAN data center fabric, so claiming tunnel conversion is technically inaccurate and irrelevant to the design justification.
- ✗
It eliminates the need for any underlay routing protocol because BGP carries all traffic between leaf switches
Why it's wrong here
EVPN still requires a fully routed underlay to provide VTEP-to-VTEP IP reachability; BGP EVPN runs as an overlay on top of that underlay. Saying it eliminates the underlay protocol is incorrect because the loopback addresses of VTEPs must be reachable across the fabric. The underlay and overlay serve distinct roles and both remain necessary.
- ✗
It removes the requirement for a loopback interface on each VTEP by using physical interface addresses
Why it's wrong here
A stable loopback address is essential on each VTEP because it serves as the tunnel source and is advertised in EVPN Type-3 routes. Using physical interface addresses would break tunnel stability if a link failed. EVPN does not remove the loopback requirement; it depends on loopbacks being reachable and consistently advertised across the fabric underlay.
- ✓
It supports multihoming of servers to two leaf switches with all-active forwarding using Ethernet Segment identifiers
Why this is correct
EVPN defines Ethernet Segment identifiers and DF election, enabling a server to dual-home to two leaf switches with all-active forwarding. This provides redundancy and better bandwidth utilization than traditional spanning-tree-based multihoming. In a flood-and-learn VXLAN design, there is no standardized control plane for all-active multihoming, so this is a clear advantage of EVPN.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Wireless Fundamentals and 802.11 Standards
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.