350-401 Virtualization Practice Question
A network engineer is troubleshooting connectivity issues in a multi-tenant environment where each tenant's traffic is isolated using VRF-Lite. The engineer notices that tenants in the same VRF cannot communicate with each other across different access switches. Which design change should be implemented to enable inter-switch VRF communication?
⚠ Common exam trap
Cisco often tests the misconception that VRF-Lite can use the global routing table for inter-switch communication, but the trap here is that VRF-Lite requires explicit Layer 3 subinterfaces on trunk links to extend VRF boundaries, not just VLANs or static routes in the global table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create trunk links with 802.1Q subinterfaces on each switch and assign each subinterface to the appropriate VRF.
VRF-Lite requires 802.1Q trunking to extend Layer 3 VRF boundaries across switches. By creating subinterfaces on trunk links and assigning each subinterface to the appropriate VRF, traffic from the same VRF on different switches can be routed through the VRF-specific routing table, enabling inter-switch communication while maintaining isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the same VLAN for all tenants and rely on VLAN ACLs.
Why it's wrong here
VLAN ACLs operate at Layer 2 and filter traffic within a broadcast domain; they cannot maintain separate routing tables or forwarding decisions per tenant. If all tenants share the same VLAN, their IP subnets and MAC addresses are visible to one another at the data-link layer, and VACLs cannot prevent ARP spoofing or other L2 attacks. Moreover, VACLs cannot resolve overlapping IP address spaces because they rely on a single L3 forwarding context, so the isolation required for multi-tenancy is fundamentally unavailable.
- ✓
Create trunk links with 802.1Q subinterfaces on each switch and assign each subinterface to the appropriate VRF.
Why this is correct
Creating an 802.1Q trunk with subinterfaces lets each switch or router terminate multiple VLANs on a single physical link, and each subinterface can be explicitly bound to a tenant's VRF. This gives each tenant an isolated routing table; the switch will route packets received on a subinterface using only the routes in that subinterface's assigned VRF. The trunk carries tagged frames for all tenants, but the VRF association ensures that traffic from tenant A's VLAN never enters tenant B's routing path, even though they share the same physical ports and trunk. This is a standard VRF-lite design for inter-switch VRF connectivity.
- ✗
Configure static routes on each switch pointing to the next-hop IP in the global routing table.
Why it's wrong here
Static routes placed in the global routing table are unaware of VRFs and cannot direct traffic that arrives on a VRF-aware interface. Even if the route points to a valid next hop in the global table, packets from a VRF will be dropped because the VRF's routing table has no corresponding route or because the next hop is not reachable from that VRF's context. Additionally, with overlapping subscriber addresses, a single global route is ambiguous and cannot select the correct egress interface. The fix would be to define separate static routes inside each VRF, not in the global table.
- ✗
Enable OSPF with a single area on all switches and redistribute between VRFs.
Why it's wrong here
OSPF running in a single area without VRF-aware configuration builds one LSDB and one SPF tree for the entire device, so it cannot distinguish tenant A's routes from tenant B's routes. Redistribution between VRFs is not a native OSPF feature; it requires route leaking between VRFs, which violates the isolation VRFs are meant to enforce and can cause routing loops if not carefully filtered. Furthermore, OSPF's router ID and neighbor relationships are global by default, so you cannot run multiple independent OSPF instances for each tenant without enabling VRF-lite (per-VRF OSPF process). Therefore, a single-area OSPF approach cannot provide the per-tenant segregation this multi-tenant network demands.
Go deeper
Related to this question
Learn chapter
Network Monitoring and Troubleshooting Tools
Key term
Virtual Routing and Forwarding
Virtual Routing and Forwarding (VRF) is a technology that allows a single physical router to operate like multiple independent routers by keeping separate routing tables and forwarding decisions for each instance.
Key term
VLAN Trunking
VLAN Trunking is a method to carry traffic for multiple VLANs over a single network link between switches or between a switch and a router.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.