Courseiva
Virtualization →mediumMultiple Choice

350-401 Virtualization Practice Question

A network engineer is troubleshooting a Cisco Nexus 9000 leaf switch that is part of a VXLAN EVPN fabric. The engineer notices that the leaf is not learning remote MAC addresses, although the underlay is operational and BGP EVPN sessions are established. Which action should the engineer take to verify that the leaf is receiving EVPN Type 2 routes?

⚠ Common exam trap

The trap here is assuming that seeing NVE peers or underlay routes is sufficient to confirm MAC learning, when actually you need to inspect the BGP EVPN table for Type 2 routes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the output of 'show bgp l2vpn evpn' on the leaf.

To verify that the leaf is receiving EVPN Type 2 routes, you must examine the BGP EVPN table. The command 'show bgp l2vpn evpn' displays all EVPN routes, including Type 2 MAC/IP advertisement routes. If these routes are missing, the leaf will not learn remote MAC addresses. Other commands like 'show nve peers' show VTEP peers but not MAC routes, and 'show vxlan interface' shows tunnel configuration, not routes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check the output of 'show vxlan interface' on the leaf.

    Why it's wrong here

    'show vxlan interface' provides information about the VXLAN tunnel interface, such as the source interface and VNI mappings. It does not display EVPN routes. While it can confirm that VXLAN is configured, it will not show whether Type 2 routes are being received. This command is useful for verifying VTEP configuration but not for EVPN route learning.

  • ✗

    Check the output of 'show ip route' on the leaf.

    Why it's wrong here

    'show ip route' displays the underlay IP routing table, which confirms reachability to remote VTEP loopbacks. It does not show EVPN routes or MAC address information. While underlay reachability is necessary, it does not verify that the leaf is receiving Type 2 routes. This command is irrelevant to EVPN route verification.

  • ✗

    Check the output of 'show nve peers' on the leaf.

    Why it's wrong here

    'show nve peers' displays the remote VTEP peers learned through the control plane. It shows the IP addresses of remote VTEPs and the VNIs associated with them. However, it does not show the specific EVPN routes (Type 2) that carry MAC addresses. If NVE peers are present, it indicates that Type 3 routes are learned, but not necessarily Type 2. This command is not the best to verify Type 2 routes.

  • ✓

    Check the output of 'show bgp l2vpn evpn' on the leaf.

    Why this is correct

    The command 'show bgp l2vpn evpn' displays the EVPN routes received from BGP peers, including Type 2 (MAC/IP advertisement) routes. If the leaf is not learning remote MACs, this command will show whether Type 2 routes are present. If they are missing, the issue may be with the BGP EVPN configuration or route reflectors. This is the correct verification step.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.