Courseiva
Architecture →easyMultiple Choice

350-401 Architecture Practice Question

A network engineer is designing a campus network and needs to ensure high availability for the core layer. Which design best practice should be implemented?

⚠ Common exam trap

Cisco often tests the misconception that the core layer should remain Layer 2 for simplicity, but in modern campus designs, the core must route at Layer 3 to avoid STP convergence delays and support ECMP load balancing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy two core switches configured with VSS or StackWise.

Deploying two core switches with VSS (Virtual Switching System) or StackWise provides both redundancy and active-active load balancing at the core layer. VSS virtualizes two physical switches into a single logical switch, eliminating the need for Spanning Tree Protocol (STP) on inter-switch links and enabling sub-second failover. This design ensures high availability by removing single points of failure and maximizing throughput between distribution and core layers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a single distribution switch to simplify management.

    Why it's wrong here

    In a campus network, the distribution layer aggregates access switches and enforces policy, so a single distribution switch becomes a single point of failure. If that switch fails or reboots, every connected access switch loses connectivity to the rest of the network, directly violating high-availability requirements. A resilient design requires at least two distribution switches using HSRP/VRRP for first-hop gateway redundancy or stacking/VSS to provide active-active forwarding.

  • ✓

    Deploy two core switches configured with VSS or StackWise.

    Why this is correct

    VSS or StackWise combines two physical core switches into one logical device, providing stateful failover and sub-second convergence between the chassis. This approach enables active-active traffic forwarding and allows downstream switches to use Cross-Stack EtherChannel (MEC), so both links carry traffic rather than one being blocked by spanning tree. Because the pair appears as a single switch, routing protocols and STP see one node, which simplifies configuration and improves redundancy compared to a standalone pair running HSRP.

  • ✗

    Configure the core layer for Layer 2 switching only.

    Why it's wrong here

    A Layer 2-only core requires inter-VLAN routing to happen at the distribution or access layers, forcing traffic to take suboptimal paths and increasing latency. Since a Layer 2 core relies on spanning tree for loop prevention, one of any redundant uplinks is always blocked, wasting bandwidth and extending failover times when the active path fails. In modern campus network designs, the core should perform Layer 3 routing to provide equal-cost multipath load balancing, fast convergence via protocols like OSPF or BGP, and to contain broadcast domains.

  • ✗

    Use spanning-tree PortFast on all core switch ports.

    Why it's wrong here

    Spanning-tree PortFast bypasses STP listening/learning states for access ports to speed up host link-up, but it is not a redundancy feature. Applying PortFast to core ports connecting to other switches or the distribution layer removes spanning tree protections on those links, so if any redundant path exists, a temporary Layer 2 loop can form and cause a broadcast storm. The core should instead use STP features like LoopGuard or root guard, or better, use VSS/StackWise to avoid STP blocking altogether; PortFast alone never provides failover.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.