350-401 Virtualization Practice Question
Exhibit
Refer to the exhibit. ! NVE configuration interface nve1 no shut source-interface Loopback0 member vni 10100 mcast-group 239.1.1.100 ! ! VRF configuration vrf context TENANT-A rd 65000:1 address-family ipv4 unicast route-target both 65000:100 exit-address-family ! ! BGP EVPN configuration router bgp 65000 neighbor 10.1.1.1 remote-as 65000 neighbor 10.1.1.1 update-source Loopback0 address-family l2vpn evpn neighbor 10.1.1.1 activate neighbor 10.1.1.1 send-community extended ! ! VLAN configuration vlan 100 vn-segment 10100 ! ! Interface configuration interface Vlan100 no shutdown vrf member TENANT-A ip address 192.168.100.1/24
An engineer configures VXLAN EVPN on a Nexus 9000 switch. The configuration is shown. The switch does not advertise any EVPN routes for VNI 10100. Which configuration change is required to fix this issue?
⚠ Common exam trap
Cisco often tests the distinction between the NVE interface configuration (which enables VXLAN encapsulation) and the BGP EVPN address-family configuration (which enables route advertisement), leading candidates to mistakenly focus on NVE or interface settings instead of the missing BGP VNI injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.
For VXLAN EVPN on a Nexus 9000, the BGP address-family l2vpn evpn must explicitly contain the 'evpn' keyword and the 'vni 10100 l2' command to advertise Layer 2 VNI routes. Without this configuration, BGP does not know to inject the VNI's MAC/VTEP information into the EVPN route table, so no EVPN routes are advertised for VNI 10100.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.
Why this is correct
The VNI must be explicitly activated under BGP EVPN. Without the 'vni 10100 l2' configuration inside address-family l2vpn evpn, BGP has no awareness of this L2 VNI and will not originate or import the type-2 (MAC/IP) and type-3 (inclusive multicast) routes needed for remote VTEPs to learn MAC addresses. Adding that command, along with 'evpn' as the address family, is what makes the control plane advertise the VNI. This is the missing configuration causing the issue.
- ✗
Remove the mcast-group from the NVE member, because EVPN uses BGP for control plane.
Why it's wrong here
The mcast-group under the NVE member is used for data-plane BUM (broadcast, unknown unicast, multicast) flooding in a traditional VXLAN multicast architecture. With EVPN, the control plane is BGP, but multicast or ingress replication may still be used for BUM traffic at the data plane. Removing mcast-group would not cause the VNI to be advertised via BGP – the failure here is the missing activation of the VNI under BGP EVPN. So while the note suggests EVPN uses BGP for control plane, removing mcast-group is not the corrective action.
- ✗
Change the source-interface to a physical interface.
Why it's wrong here
Changing the source-interface to a physical interface is the opposite of best practice. A loopback interface is recommended as the VXLAN tunnel source because it is always up, independent of any single physical link, and provides stable VTEP addressing for the control plane. The issue with VXLAN/EVPN peering is not the source interface; even with the correct loopback, BGP alone does not know which VNIs to advertise unless they are explicitly configured under the 'address-family l2vpn evpn' context.
- ✗
Add an IP address to the VLAN 100 interface in the default VRF.
Why it's wrong here
The VLAN 100 interface is intentionally assigned to a non-default VRF as part of a tenant L3 VNI design, and adding an IP in the default VRF would not help. EVPN VNI advertisement is decoupled from the SVI IP configuration; the failure is at the BGP control plane level. The issue is that the L2 VNI 10100 is not registered with BGP EVPN, so no route targets are applied and no VTEP can learn about this segment. Therefore, adding an IP address addresses a non-existent Layer 3 problem.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Route Redistribution and Filtering
Key term
Cisco Virtual Topology System
Cisco Virtual Topology System is a software-defined networking solution that creates and manages virtual network overlays across physical and virtual infrastructure for enterprise networks.
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.