Courseiva
Virtualization →hardMultiple Choice

350-401 Virtualization Practice Question

Exhibit

Refer to the exhibit.

! NVE configuration
interface nve1
 no shut
 source-interface Loopback0
 member vni 10100
  mcast-group 239.1.1.100
!
! VRF configuration
vrf context TENANT-A
 rd 65000:1
 address-family ipv4 unicast
  route-target both 65000:100
 exit-address-family
!
! BGP EVPN configuration
router bgp 65000
 neighbor 10.1.1.1 remote-as 65000
 neighbor 10.1.1.1 update-source Loopback0
 address-family l2vpn evpn
  neighbor 10.1.1.1 activate
  neighbor 10.1.1.1 send-community extended
!
! VLAN configuration
vlan 100
 vn-segment 10100
!
! Interface configuration
interface Vlan100
 no shutdown
 vrf member TENANT-A
 ip address 192.168.100.1/24

An engineer configures VXLAN EVPN on a Nexus 9000 switch. The configuration is shown. The switch does not advertise any EVPN routes for VNI 10100. Which configuration change is required to fix this issue?

⚠ Common exam trap

Cisco often tests the distinction between the NVE interface configuration (which enables VXLAN encapsulation) and the BGP EVPN address-family configuration (which enables route advertisement), leading candidates to mistakenly focus on NVE or interface settings instead of the missing BGP VNI injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.

For VXLAN EVPN on a Nexus 9000, the BGP address-family l2vpn evpn must explicitly contain the 'evpn' keyword and the 'vni 10100 l2' command to advertise Layer 2 VNI routes. Without this configuration, BGP does not know to inject the VNI's MAC/VTEP information into the EVPN route table, so no EVPN routes are advertised for VNI 10100.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.

    Why this is correct

    The VNI must be explicitly activated under BGP EVPN. Without the 'vni 10100 l2' configuration inside address-family l2vpn evpn, BGP has no awareness of this L2 VNI and will not originate or import the type-2 (MAC/IP) and type-3 (inclusive multicast) routes needed for remote VTEPs to learn MAC addresses. Adding that command, along with 'evpn' as the address family, is what makes the control plane advertise the VNI. This is the missing configuration causing the issue.

  • ✗

    Remove the mcast-group from the NVE member, because EVPN uses BGP for control plane.

    Why it's wrong here

    The mcast-group under the NVE member is used for data-plane BUM (broadcast, unknown unicast, multicast) flooding in a traditional VXLAN multicast architecture. With EVPN, the control plane is BGP, but multicast or ingress replication may still be used for BUM traffic at the data plane. Removing mcast-group would not cause the VNI to be advertised via BGP – the failure here is the missing activation of the VNI under BGP EVPN. So while the note suggests EVPN uses BGP for control plane, removing mcast-group is not the corrective action.

  • ✗

    Change the source-interface to a physical interface.

    Why it's wrong here

    Changing the source-interface to a physical interface is the opposite of best practice. A loopback interface is recommended as the VXLAN tunnel source because it is always up, independent of any single physical link, and provides stable VTEP addressing for the control plane. The issue with VXLAN/EVPN peering is not the source interface; even with the correct loopback, BGP alone does not know which VNIs to advertise unless they are explicitly configured under the 'address-family l2vpn evpn' context.

  • ✗

    Add an IP address to the VLAN 100 interface in the default VRF.

    Why it's wrong here

    The VLAN 100 interface is intentionally assigned to a non-default VRF as part of a tenant L3 VNI design, and adding an IP in the default VRF would not help. EVPN VNI advertisement is decoupled from the SVI IP configuration; the failure is at the BGP control plane level. The issue is that the L2 VNI 10100 is not registered with BGP EVPN, so no route targets are applied and no VTEP can learn about this segment. Therefore, adding an IP address addresses a non-existent Layer 3 problem.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.