Courseiva
Virtualization →mediumMultiple Choice

350-401 Virtualization Practice Question

A network engineer is deploying a Cisco Nexus 9000 leaf-spine fabric with VXLAN EVPN. The design requires that all leaf switches act as VTEPs and that each leaf learn remote MAC addresses only from the fabric control plane rather than from data-plane flooding. Which configuration on the leaf switches accomplishes this requirement?

⚠ Common exam trap

The trap here is assuming that enabling ARP suppression or flooding achieves control-plane MAC learning, when only the host-reachability protocol tied to BGP EVPN does that.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the NVE interface with `source-interface loopback0` and enable `host-reachability protocol bgp`.

The requirement is control-plane MAC learning across the VXLAN fabric. Binding the NVE interface to a loopback and enabling BGP as the host-reachability protocol makes the leaf a VTEP that exchanges EVPN MAC/IP and IMET routes with its peers. Remote MAC addresses are then resolved from BGP EVPN advertisements, eliminating flood-and-learn. Flooding, static ingress replication, and ARP suppression alone cannot satisfy that control-plane requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure `arp suppression` on all leaf switches so that ARP requests are answered locally without control-plane involvement.

    Why it's wrong here

    ARP suppression reduces ARP flooding by answering requests from a local cache, but it depends on the control plane having already populated that cache with EVPN MAC/IP routes. On its own it does not establish remote host reachability and would leave the cache empty. It is an optimization layered on top of EVPN, not a replacement for enabling BGP host reachability.

  • ✓

    Configure the NVE interface with `source-interface loopback0` and enable `host-reachability protocol bgp`.

    Why this is correct

    Enabling BGP as the host-reachability protocol on the NVE interface causes the leaf to advertise and learn MAC/IP and IMET routes through EVPN, so remote MAC addresses are resolved from the control plane instead of flood-and-learn. The loopback source provides a stable VTEP address reachable across the underlay, which is required for the EVPN peering and for tunnel endpoints to be consistent.

  • ✗

    Configure `flooding enable` globally on each leaf so unknown unicast frames are replicated to all VTEPs in the fabric.

    Why it's wrong here

    Enabling flooding allows unknown unicast to be replicated to remote VTEPs, which is exactly the data-plane learning behaviour the design excludes. It does not provide a control-plane mechanism for MAC learning, so it fails the stated requirement. Flooding may be useful as a fallback, but it cannot replace EVPN host reachability and is not the intended solution here.

  • ✗

    Configure `ingress-replication protocol static` on the NVE interface with a list of all remote VTEP addresses.

    Why it's wrong here

    Static ingress replication defines a fixed list of replication peers for BUM traffic, but it does not provide MAC or IP host reachability through the control plane. Remote MACs would still be learned through data-plane flooding, violating the requirement. Static peer lists also scale poorly and must be updated manually whenever a VTEP is added, which contradicts the automated fabric design.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.