350-401 Virtualization Practice Question
An engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint in a spine-leaf fabric. The requirement is that the switch must perform VXLAN encapsulation and decapsulation in hardware without relying on the supervisor CPU, and it must support distributed anycast gateway for the tenant subnets. Which feature set must be enabled to meet these requirements?
⚠ Common exam trap
A common mix-up: candidates confuse a centralized management or SDN platform with the on-switch feature set that actually delivers hardware VXLAN forwarding and distributed anycast gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco NX-OS with the VXLAN feature and distributed anycast gateway enabled
Nexus 9000 switches support VXLAN encapsulation and decapsulation in hardware once the VXLAN feature is enabled, keeping forwarding off the supervisor CPU. A distributed anycast gateway configured with a shared virtual IP and MAC across leaf switches provides efficient first-hop routing for tenant subnets, meeting both requirements for this VXLAN Tunnel Endpoint design.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Traditional Layer 2 switching with STP
Why it's wrong here
Traditional Layer 2 switching with Spanning Tree Protocol does not provide VXLAN encapsulation or a distributed anycast gateway. STP actively blocks redundant paths, which is incompatible with the leaf-spine fabric requirement of using all links. This approach also cannot extend Layer 2 segments across the IP underlay, so it fails both the hardware VXLAN and anycast gateway requirements described.
- ✓
Cisco NX-OS with the VXLAN feature and distributed anycast gateway enabled
Why this is correct
On Nexus 9000 switches, enabling the VXLAN feature allows the hardware ASIC to perform VXLAN encapsulation and decapsulation at line rate, avoiding supervisor CPU involvement. Configuring a distributed anycast gateway with the same virtual IP and MAC on every leaf provides optimal first-hop routing for tenant subnets. Together these features satisfy both the hardware-based VXLAN data plane and the anycast gateway design requirement.
- ✗
Cisco ACI with a fabric-wide VXLAN pool
Why it's wrong here
Cisco ACI is a policy-driven SDN architecture managed by the APIC controller, not a feature set configured on a standalone Nexus 9000 in a VXLAN EVPN spine-leaf fabric. While ACI uses VXLAN internally, adopting it would replace the manual NX-OS configuration model entirely. This scenario calls for enabling features on the switch itself, so ACI does not match the stated requirement.
- ✗
Cisco Nexus Dashboard with fabric controller mode
Why it's wrong here
Cisco Nexus Dashboard provides centralized visibility, orchestration, and controller services across multiple fabrics, but it does not enable per-switch hardware VXLAN forwarding or anycast gateway functionality. The data-plane capabilities required here must be configured directly on the Nexus 9000 through NX-OS features. Nexus Dashboard alone cannot deliver the encapsulation and distributed gateway behavior the scenario demands.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
Cisco Virtual Topology System
Cisco Virtual Topology System is a software-defined networking solution that creates and manages virtual network overlays across physical and virtual infrastructure for enterprise networks.
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.