Courseiva
Virtualization →hardMultiple Choice

350-401 Virtualization Practice Question

An engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint in a spine-leaf fabric. The requirement is that the switch must perform VXLAN encapsulation and decapsulation in hardware without relying on the supervisor CPU, and it must support distributed anycast gateway for the tenant subnets. Which feature set must be enabled to meet these requirements?

⚠ Common exam trap

A common mix-up: candidates confuse a centralized management or SDN platform with the on-switch feature set that actually delivers hardware VXLAN forwarding and distributed anycast gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco NX-OS with the VXLAN feature and distributed anycast gateway enabled

Nexus 9000 switches support VXLAN encapsulation and decapsulation in hardware once the VXLAN feature is enabled, keeping forwarding off the supervisor CPU. A distributed anycast gateway configured with a shared virtual IP and MAC across leaf switches provides efficient first-hop routing for tenant subnets, meeting both requirements for this VXLAN Tunnel Endpoint design.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Traditional Layer 2 switching with STP

    Why it's wrong here

    Traditional Layer 2 switching with Spanning Tree Protocol does not provide VXLAN encapsulation or a distributed anycast gateway. STP actively blocks redundant paths, which is incompatible with the leaf-spine fabric requirement of using all links. This approach also cannot extend Layer 2 segments across the IP underlay, so it fails both the hardware VXLAN and anycast gateway requirements described.

  • ✓

    Cisco NX-OS with the VXLAN feature and distributed anycast gateway enabled

    Why this is correct

    On Nexus 9000 switches, enabling the VXLAN feature allows the hardware ASIC to perform VXLAN encapsulation and decapsulation at line rate, avoiding supervisor CPU involvement. Configuring a distributed anycast gateway with the same virtual IP and MAC on every leaf provides optimal first-hop routing for tenant subnets. Together these features satisfy both the hardware-based VXLAN data plane and the anycast gateway design requirement.

  • ✗

    Cisco ACI with a fabric-wide VXLAN pool

    Why it's wrong here

    Cisco ACI is a policy-driven SDN architecture managed by the APIC controller, not a feature set configured on a standalone Nexus 9000 in a VXLAN EVPN spine-leaf fabric. While ACI uses VXLAN internally, adopting it would replace the manual NX-OS configuration model entirely. This scenario calls for enabling features on the switch itself, so ACI does not match the stated requirement.

  • ✗

    Cisco Nexus Dashboard with fabric controller mode

    Why it's wrong here

    Cisco Nexus Dashboard provides centralized visibility, orchestration, and controller services across multiple fabrics, but it does not enable per-switch hardware VXLAN forwarding or anycast gateway functionality. The data-plane capabilities required here must be configured directly on the Nexus 9000 through NX-OS features. Nexus Dashboard alone cannot deliver the encapsulation and distributed gateway behavior the scenario demands.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.