Courseiva
Virtualization →mediumMultiple Choice

350-401 Virtualization Practice Question

A network engineer is configuring a Cisco Nexus 9000 switch with VXLAN EVPN. The engineer wants to ensure that the switch can forward traffic between VLANs that are mapped to the same VXLAN Network Identifier (VNI) but are on different leaf switches. Which component is responsible for mapping the VLAN to the VNI on the ingress leaf switch?

⚠ Common exam trap

Watch out — candidates often confuse the VTEP with the VLAN-to-VNI mapping, as the VTEP uses the mapping but is not the mapping itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VLAN-to-VNI mapping

The VLAN-to-VNI mapping is the component that associates a VLAN with a VNI on the ingress leaf switch. When a frame enters the access port, the switch uses this mapping to encapsulate it in VXLAN with the correct VNI. EVPN route type 2 is for MAC/IP advertisement, the VTEP encapsulates and decapsulates VXLAN traffic, and ingress replication is used for BUM traffic handling. Only the VLAN-to-VNI mapping directly performs the required function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ingress replication

    Why it's wrong here

    Ingress replication is a method for handling broadcast, unknown unicast, and multicast (BUM) traffic in VXLAN. It involves the ingress VTEP replicating BUM frames to all other VTEPs in the VNI. It does not perform VLAN-to-VNI mapping. In EVPN, ingress replication is often replaced by multicast or assisted replication. This mechanism is about flooding, not about mapping VLANs to VNIs. Thus, it is not the correct answer.

  • ✓

    VLAN-to-VNI mapping

    Why this is correct

    The VLAN-to-VNI mapping is configured on the ingress leaf switch to associate a VLAN with a VNI. When a frame arrives on an access port in a VLAN, the switch uses this mapping to encapsulate the frame in VXLAN with the corresponding VNI. This allows Layer 2 connectivity to be extended across the VXLAN fabric. The mapping is typically configured under the VLAN configuration or via a VLAN-VNI mapping command. Without this mapping, the switch would not know which VNI to use for encapsulation.

  • ✗

    VXLAN Tunnel Endpoint (VTEP)

    Why it's wrong here

    The VXLAN Tunnel Endpoint (VTEP) is responsible for encapsulating and decapsulating VXLAN traffic. It uses the VLAN-to-VNI mapping to determine the VNI, but the VTEP itself is not the mapping. The VTEP is a logical interface (often a loopback) that sources and terminates VXLAN tunnels. While the VTEP uses the mapping, it does not define it. The question asks for the component that maps VLAN to VNI, which is the mapping configuration, not the VTEP.

  • ✗

    EVPN route type 2

    Why it's wrong here

    EVPN route type 2 is used to advertise MAC addresses and IP addresses (for ARP suppression) across the EVPN fabric. It helps with MAC address learning and host mobility, but it does not perform the VLAN-to-VNI mapping. The mapping is a local configuration on the ingress leaf switch. Route type 2 is used for control-plane learning, not for data-plane encapsulation decisions. Therefore, it is not responsible for mapping VLAN to VNI on the ingress leaf.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.