350-401 Virtualization Practice Question
A network engineer is deploying a Cisco Nexus 9000 leaf-spine fabric with VXLAN EVPN. The design requires that all leaf switches act as VTEPs and that each leaf learn remote MAC addresses only from the fabric control plane rather than from data-plane flooding. Which configuration on the leaf switches accomplishes this requirement?
⚠ Common exam trap
The trap here is assuming that enabling ARP suppression or flooding achieves control-plane MAC learning, when only the host-reachability protocol tied to BGP EVPN does that.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the NVE interface with `source-interface loopback0` and enable `host-reachability protocol bgp`.
The requirement is control-plane MAC learning across the VXLAN fabric. Binding the NVE interface to a loopback and enabling BGP as the host-reachability protocol makes the leaf a VTEP that exchanges EVPN MAC/IP and IMET routes with its peers. Remote MAC addresses are then resolved from BGP EVPN advertisements, eliminating flood-and-learn. Flooding, static ingress replication, and ARP suppression alone cannot satisfy that control-plane requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure `arp suppression` on all leaf switches so that ARP requests are answered locally without control-plane involvement.
Why it's wrong here
ARP suppression reduces ARP flooding by answering requests from a local cache, but it depends on the control plane having already populated that cache with EVPN MAC/IP routes. On its own it does not establish remote host reachability and would leave the cache empty. It is an optimization layered on top of EVPN, not a replacement for enabling BGP host reachability.
- ✓
Configure the NVE interface with `source-interface loopback0` and enable `host-reachability protocol bgp`.
Why this is correct
Enabling BGP as the host-reachability protocol on the NVE interface causes the leaf to advertise and learn MAC/IP and IMET routes through EVPN, so remote MAC addresses are resolved from the control plane instead of flood-and-learn. The loopback source provides a stable VTEP address reachable across the underlay, which is required for the EVPN peering and for tunnel endpoints to be consistent.
- ✗
Configure `flooding enable` globally on each leaf so unknown unicast frames are replicated to all VTEPs in the fabric.
Why it's wrong here
Enabling flooding allows unknown unicast to be replicated to remote VTEPs, which is exactly the data-plane learning behaviour the design excludes. It does not provide a control-plane mechanism for MAC learning, so it fails the stated requirement. Flooding may be useful as a fallback, but it cannot replace EVPN host reachability and is not the intended solution here.
- ✗
Configure `ingress-replication protocol static` on the NVE interface with a list of all remote VTEP addresses.
Why it's wrong here
Static ingress replication defines a fixed list of replication peers for BUM traffic, but it does not provide MAC or IP host reachability through the control plane. Remote MACs would still be learned through data-plane flooding, violating the requirement. Static peer lists also scale poorly and must be updated manually whenever a VTEP is added, which contradicts the automated fabric design.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
Key term
Cisco Virtual Topology System
Cisco Virtual Topology System is a software-defined networking solution that creates and manages virtual network overlays across physical and virtual infrastructure for enterprise networks.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.